NetInfoMiner: High-level information extraction from network traffic

Ahmad Amro, Sultan Almuhammadi, Sami Zhioua

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Due to the rapid increase of the Internet traffic encryption HTTPS, and the newly adopted protocols HTTP2 and SPDY, the need for a comprehensive high-level information extraction tool that supports the new protocols becomes essential for critical applications such as digital and network forensic and web penetration testing. In spite of the availability of big data from the Internet traffic, current network data mining tools do not support encrypted network traffic and the new protocols. This paper proposes a new tool for extracting high-level information such as visited links, user credentials and session cookies from HTTP and HTTPS protocols. It also allows extraction of user credentials and session cookies from HTTP2 and SPDY.

Original languageEnglish
Title of host publication2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages143-150
Number of pages8
ISBN (Electronic)9781509030156
DOIs
Publication statusPublished - 17 Mar 2017
Externally publishedYes
Event2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017 - Jeju Island, Korea, Republic of
Duration: 13 Feb 201716 Feb 2017

Publication series

Name2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017

Conference

Conference2017 IEEE International Conference on Big Data and Smart Computing, BigComp 2017
Country/TerritoryKorea, Republic of
CityJeju Island
Period13/02/1716/02/17

Keywords

  • Big data
  • HTTP
  • HTTP2
  • HTTPS
  • SPDY
  • data mining
  • traffic analysis

Fingerprint

Dive into the research topics of 'NetInfoMiner: High-level information extraction from network traffic'. Together they form a unique fingerprint.

Cite this