<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>University of Isfahan &amp; Iranian Society of Cryptology</PublisherName>
				<JournalTitle>Journal of Computing and Security</JournalTitle>
				<Issn>2322-4460</Issn>
				<Volume>3</Volume>
				<Issue>2</Issue>
				<PubDate PubStatus="epublish">
					<Year>2016</Year>
					<Month>04</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>A Hybrid Method based on Statistical Features and Packet Content Analysis to Identify Major Network Tunneling Protocols</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>95</FirstPage>
			<LastPage>110</LastPage>
			<ELocationID EIdType="pii">22189</ELocationID>
			
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Keihan</FirstName>
					<LastName>Kazemi</LastName>
<Affiliation>PhD Candidate</Affiliation>

</Author>
<Author>
					<FirstName>Ali</FirstName>
					<LastName>Fanian</LastName>
<Affiliation>Professor Assistance in isfahan university of thenology</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2016</Year>
					<Month>04</Month>
					<Day>20</Day>
				</PubDate>
			</History>
		<Abstract>Network traffic identification is an essential component for effective network analysis and management. Signature-based and machine learning techniques are the two most important methods in network traffic analysis. Due to the strengths and weaknesses of these two approaches, their combination can strengthen them and remove the weaknesses of each in detection process. In this article, a hybrid method is introduced, to identify major network tunneling protocols. This method can detect the well-known tunneling protocols by combining signature-based methods and statistical analysis techniques through a clustering algorithm. In this proposed method, the clustering process is refined by the feedback of signature-base method. Since, in semi-supervised clustering, it is important to gain most informative data to improve the clustering performance, in the proposed clustering method, a new active learning approach is introduced for selecting informative constraints. In this hybrid method, four tunneling protocols (L2TP, PPTP, IPsec and OpenVPN) are applied. The obtained results indicate that this proposed hybrid method significantly increases accuracy and cluster purity, and these protocols are identified with high accuracy and low processing cost.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Traffic Detection</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Tunneling Protocols</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Packet Payload Analysis</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Semi-Supervised Clustering</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Active Learning</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://jcomsec.ui.ac.ir/article_22189_06d4344d35a564ea379298a0c06637ed.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
