Passive Measurement Method For Unknown Network Protocol Identification and Classification

Norayu, Abd Ghani (2010) Passive Measurement Method For Unknown Network Protocol Identification and Classification. Masters thesis, UTeM.

[img] Text (24 Page)
Passive Measurement Method For Unknown Network Protocol Identification and Classification.pdf - Submitted Version

Download (2MB)

Abstract

Network traffic monitoring is a way for enterprises to meet performance, security and compliance goals. Yet implementing network traffic monitoring tools can also pose a series of challenges that range from difficulty in identifying exact network traffic to trouble finding the right tools and strategies for monitoring. Software protocol analyzer is a popular tool in helping network administrator to perform network traffic monitoring. In view of the fact that, accuracy in identification and classification of network packet could advanced network monitoring, and better understanding of the operational networks applications. Therefore, every packets running on the network should be able to be recognized and accurately defined to optimize network resources· usage and return of investment. Anyhow, the capability of network protocol analyzer in decoding network traffic could be a challenge to the network administrator. Capturing network traffic with unknown network protocol is a challenge to provide efficient and accurate network service. This work is focusing on to identify and reclassify the unknown network protocol in UTeM network. UNTICED methodology proposed in this research able to accurately identify and reclassify unknown network protocol in the university network. While many software protocol anal y~er vendor claims to provide accurate protocol classification, research finding confirms that different software protocol analyzer classified protocol differently. For this reason the accuracy of network protocol analyzer claimed is to confirm tool dependent.

Item Type: Thesis (Masters)
Uncontrolled Keywords: Computer networks, TCP/IP (Computer network protocol), Internetworking (Telecommunication)
Subjects: T Technology > T Technology (General)
T Technology > TK Electrical engineering. Electronics Nuclear engineering
Divisions: Library > Tesis > FTMK
Depositing User: Mr. Thaqif Mohd Isa
Date Deposited: 29 Jan 2016 03:31
Last Modified: 29 Jan 2016 03:31
URI: http://eprints.utem.edu.my/id/eprint/15484
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item