IMRG Workshop on Application Classi cation and Identi cation Report Tim Strayer BBN Technologies Mark Allman mallman@icir.org Shudong Jin Case Western Reserve University ICSI Grenville Armitage Swinburne University strayer bbn.com Steve Bellovin Columbia University garmitage@swin.edu.au Andrew W. Moore University of Cambridge smb@cs.columbia.edu jins@case.edu andrew.moore@cl.cam.ac.uk This article is an editorial note submitted to CCR. It has NOT been peer reviewed. Authors take full responsibility for this article s technical content. Comments can be posted through CCR Online. Categories and Subject Descriptors: C.2.0 General General Terms: Documentation Keywords: Application Identi cation and Characterization, Workshop Report conversations and relationships between servers and clients. The key points of the remainder of the talk are: ¢ Until a full ow is decoded that is, the content of the ow is examined and the intent of the ow is ascertained it is di cult to know what is really going on in the ow. The content is what really identi es an application, not the mechanisms for getting the content to and from the endpoints. Andrew showed that very good accuracy is achieved only by deeply inspecting the tra c, but that this method is time consuming and computationally expensive. Further, there will
/lp/association-for-computing-machinery/imrg-workshop-on-application-classification-and-identification-report-RYLKs0eVdv