Stability of Flow Features for the Identification of Internet Applications

Oliveira, M. Rosário; Valadas, Rui; Pietrzyk, M.; Collange, D.

Proceedings of 16th International Telecommunications Network Strategy and Planning Symposium (Networks), September 17-19, Funchal, Portugal, (2014), 1 - 6

One important requirement associated with the deployment of large scale classification infrastructures is the portability of classifiers, which allows a small number of pre-trained classifiers to be used on many sites and time periods. The portability can be severely degraded if the flow features used in the classification process lack stability, i.e. if they do not preserve their most relevant statistical properties across different sites and time periods. In this paper we propose a statistical procedure to evaluate the stability of flow features, which resorts to the notion of effect size. The procedure is used challenge the stability of popular flow features, such as the direction and size of the first four packets of a TCP connection. Our results, obtained with three high-quality traffic traces, clearly show that only some applications are portable, when using these features as discriminators. We also provide evidence of these findings based on the operation of the protocols underlying the Internet applications.