{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T14:16:31Z","timestamp":1761401791227,"version":"3.41.0"},"reference-count":117,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2016,6,18]],"date-time":"2016-06-18T00:00:00Z","timestamp":1466208000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Peer-to-Peer Netw. Appl."],"published-print":{"date-parts":[[2017,9]]},"DOI":"10.1007\/s12083-016-0471-2","type":"journal-article","created":{"date-parts":[[2016,6,18]],"date-time":"2016-06-18T07:12:32Z","timestamp":1466233952000},"page":"1182-1203","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Identifying P2P traffic: A survey"],"prefix":"10.1007","volume":"10","author":[{"given":"Max","family":"Bhatia","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mritunjay Kumar","family":"Rai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,6,18]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"Hurley J, Garcia-Palacios E, Sezer S (2009) Classification of P2P and HTTP using specific protocol characteristics. Lecture notes in The Internet of the Future, Proceedings of 15th Open European Summer School and IFIP TC6.6 Workshop, EUNICE 2009, Barcelona, Spain, vol. 5733, pp 31\u201340","key":"471_CR1","DOI":"10.1007\/978-3-642-03700-9_4"},{"issue":"6","key":"471_CR2","doi-asserted-by":"crossref","first-page":"6417","DOI":"10.1016\/j.eswa.2010.09.114","volume":"38","author":"M Mohammadi","year":"2011","unstructured":"Mohammadi M, Raahemi B, Akbari A, Moeinzadeh H, Nasershari B (2011) Genetic-based minimum classification error mapping for accurate identifying Peer-to-Peer applications in the internet traffic. Expert Syst Appl: Int J 38(6):6417\u20136423","journal-title":"Expert Syst Appl: Int J"},{"issue":"2","key":"471_CR3","doi-asserted-by":"crossref","first-page":"219","DOI":"10.1109\/TNET.2004.826277","volume":"12","author":"S Sen","year":"2004","unstructured":"Sen S, Wang J (2004) Analyzing peer-to-peer traffic across large networks. IEEE\/ACM Trans Networking 12(2):219\u2013232","journal-title":"IEEE\/ACM Trans Networking"},{"doi-asserted-by":"crossref","unstructured":"Dai L, Yang J, Lin L (2010) A comprehensive system for P2P classification. In: 2nd IEEE international conference on network infrastructure and digital content, pp 561\u2013563","key":"471_CR4","DOI":"10.1109\/ICNIDC.2010.5657830"},{"doi-asserted-by":"crossref","unstructured":"Chu H, Yi H, Zhang H (2011) A new P2P traffic identification methodology based on flow statistics. In: 3rd IEEE international conference on communication software and networks (ICCSN 2011), pp 277\u2013281","key":"471_CR5","DOI":"10.1109\/ICCSN.2011.6014440"},{"issue":"7","key":"471_CR6","doi-asserted-by":"crossref","first-page":"1055","DOI":"10.1016\/j.comnet.2009.10.009","volume":"54","author":"R Keralapura","year":"2010","unstructured":"Keralapura R, Nucci A, Chuah C-N (2010) A novel self-learning architecture for p2p traffic classification in high speed networks. Comput Netw 54(7):1055\u20131068","journal-title":"Comput Netw"},{"doi-asserted-by":"crossref","unstructured":"Azzouna NB, Guillemin F (2003) Analysis of ADSL traffic on an IP backbone link. In: IEEE Global Telecommunication Conference (GLOBECOM\u201903), vol. 7, pp. 3742\u20133746","key":"471_CR7","DOI":"10.1109\/GLOCOM.2003.1258932"},{"unstructured":"Schulze H, Mochalski K (2007) Internet study 2007. Tech. report, ipoque","key":"471_CR8"},{"unstructured":"Karagiannis T, Broido A, Brownlee N, Claffy KC, Faloutsos M (2004) File-sharing in the Internet: a characterization of P2P traffic in the backbone. Tech. report","key":"471_CR9"},{"doi-asserted-by":"crossref","unstructured":"Madhukar A, Williamson C (2006) A longitudinal study of P2P traffic classification. In: Proceedings of 14th IEEE international symposium on modeling, analysis, and simulation of computer and telecommunication systems, Washington, DC, USA, pp. 179\u2013188","key":"471_CR10","DOI":"10.1109\/MASCOTS.2006.6"},{"doi-asserted-by":"crossref","unstructured":"Nguyen TTT, Armitage G (2009) A survey of techniques for internet traffic classification using machine learning. In: IEEE Communications surveys and tutorials, vol. 10, no.4","key":"471_CR11","DOI":"10.1109\/SURV.2008.080406"},{"issue":"3","key":"471_CR12","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1109\/SURV.2009.090304","volume":"11","author":"A Callado","year":"2009","unstructured":"Callado A, Kamienski C, Szabo G, Gero B, Kelner J, Fernandes S, Sadok D (2009) A survey on internet traffic identification. IEEE Commun Surv Tutorials 11(3):37\u201352","journal-title":"IEEE Commun Surv Tutorials"},{"issue":"6","key":"471_CR13","doi-asserted-by":"crossref","first-page":"790","DOI":"10.1016\/j.comnet.2008.11.016","volume":"53","author":"W Li","year":"2009","unstructured":"Li W, Canini M, Moore AW, Bolla R (2009) Efficient application identification and the temporal and spatial stability of classification schema. Comput Netw 53(6):790\u2013809","journal-title":"Comput Netw"},{"issue":"3","key":"471_CR14","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1109\/4236.968834","volume":"5","author":"C Williamson","year":"2001","unstructured":"Williamson C (2001) Internet traffic measurement. IEEE Internet Comput 5(3):70\u201374","journal-title":"IEEE Internet Comput"},{"doi-asserted-by":"crossref","unstructured":"McGregor T (2002) Quality in measurement: beyond the deployment barrier. In: Proceedings of the symposium on applications and the internet workshops (SAINT), IEEE Computer Society, pp 66\u201373","key":"471_CR15","DOI":"10.1109\/SAINTW.2002.994555"},{"doi-asserted-by":"crossref","unstructured":"Paxson V (2004) Strategies for sound Internet measurement. In: Proceedings of the ACM SIGCOMM Internet Measurement Conference (IMC 2004), NY, USA, pp 263\u2013271","key":"471_CR16","DOI":"10.1145\/1028788.1028824"},{"unstructured":"Enterprise network monitoring tools \u2013 network security system \u2013 application performance monitoring. http:\/\/www.endace.com","key":"471_CR17"},{"unstructured":"IPOQUE (2015) Bandwidth management with deep packet inspection. http:\/\/www.ipoque.com","key":"471_CR18"},{"unstructured":"WildPackets: Network analyzer, voip monitoring, protocol analysis. http:\/\/www.wildpackets.com","key":"471_CR19"},{"unstructured":"Intelligent real-time network analysis. http:\/\/www.napatech.com","key":"471_CR20"},{"unstructured":"SNORT. http:\/\/www.snort.org","key":"471_CR21"},{"unstructured":"Bro intrusion detection system. http:\/\/bro-ids.org","key":"471_CR22"},{"unstructured":"Wireshark, go deep. http:\/\/www.wireshark.org","key":"471_CR23"},{"unstructured":"ETTERCAP. http:\/\/ettercap.sourceforge.net","key":"471_CR24"},{"unstructured":"Claffy KC, McCreary S (1999) Internet measurement and data analysis: passive and active measurement. In: American Statistical Association","key":"471_CR25"},{"issue":"3","key":"471_CR26","doi-asserted-by":"crossref","first-page":"472","DOI":"10.1214\/088342304000000206","volume":"19","author":"NG Duffield","year":"2004","unstructured":"Duffield NG (2004) Sampling for passive internet measurement: a review. Stat Sci 19(3):472\u2013498","journal-title":"Stat Sci"},{"issue":"5","key":"471_CR27","doi-asserted-by":"crossref","first-page":"933","DOI":"10.1109\/TNET.2005.852874","volume":"13","author":"N Duffield","year":"2005","unstructured":"Duffield N, LUND C, Thorup M (2005) Estimating flow distributions from sampled flow statistics. IEEE\/ACM Trans Netw 13(5):933\u2013946","journal-title":"IEEE\/ACM Trans Netw"},{"issue":"8","key":"471_CR28","doi-asserted-by":"crossref","first-page":"1481","DOI":"10.1109\/49.464717","volume":"13","author":"KC Claffy","year":"1995","unstructured":"Claffy KC, Braun H-W, Polyzos GC (1995) A parameterizable methodology for Internet traffic flow profiling. IEEE J Sel Areas Commun 13(8):1481\u20131494","journal-title":"IEEE J Sel Areas Commun"},{"unstructured":"Apisdorf J, Claffy KC, Thompson K, Wilder R (1996) OC3MON: flexible, affordable, high performance statistics collection. In: Proceedings of the 10th USENIX conference on systems administration (LISA 1996), USENIX Association, Berkeley, CA, USA, pp. 97\u2013112","key":"471_CR29"},{"unstructured":"Moore D, Keys K, Koga R, Lagache E, Claffy KC (2001) The CoralReef software suite as a tool for system and network administrators. In: Proceedings of the 15th USENIX conference on system administration (LISA 2001), USENIX Association, Berkeley, CA, USA, pp 133\u2013144","key":"471_CR30"},{"unstructured":"CISCO NETFLOW. http:\/\/www.cisco.com\/web\/go\/netflow","key":"471_CR31"},{"unstructured":"IETF (2008) Specification of the IP flow information export (IPFIX) protocol for the exchange of IP traffic flow information. In: RFC 5101","key":"471_CR32"},{"doi-asserted-by":"crossref","unstructured":"Allman M, Paxson V (2007) Issues and etiquette concerning use of shared measurement data. In: Proceedings of the 7th ACM SIGCOMM conference on Internet Measurement (IMC 2007), ACM, New York, NY, USA, pp 135\u2013140","key":"471_CR33","DOI":"10.1145\/1298306.1298327"},{"unstructured":"TCPDUMP\/LIBPCAP public repository. http:\/\/www.tcpdump.org","key":"471_CR34"},{"unstructured":"WINDUMP. tcpdump forWindows usingWinPcap. http:\/\/www.winpcap.org\/windump","key":"471_CR35"},{"unstructured":"Jurga RE, Hulb\u00f3j MM (2007) Packet sampling for network monitoring. Technical report, CERN - HP Procurve openlab project","key":"471_CR36"},{"doi-asserted-by":"crossref","unstructured":"Sperotto A, Sadre R, Vliet F, Pras A (2009) A labeled data set for flow-based intrusion detection. In: Proceedings of the 9th IEEE international workshop on ip operations and management(IPOM 2009) (Venice, Italy, Oct.), LNCS Series, Springer-Verlag, Berlin Heidelberg, vol. 5843, pp 39\u201350","key":"471_CR37","DOI":"10.1007\/978-3-642-04968-2_4"},{"doi-asserted-by":"crossref","unstructured":"Zuev D, Moore AW (2005) Traffic classification using a statistical approach. In: Proceedings of the passive and active measurement conference (PAM 2005), LNCS Series, Springer-Verlag, Berlin Heidelberg, vol. 3431, pp 321\u2013324","key":"471_CR38","DOI":"10.1007\/978-3-540-31966-5_25"},{"doi-asserted-by":"crossref","unstructured":"Karagiannis T, Papagiannaki K, Faloutsos M (2005) BLINC: multilevel traffic classification in the dark. In: Proceedings of the ACM SIGCOMM conferenece. on applications, technologies, architectures, and protocols for computer communications, ACM, New York, NY, USA, vol. 35, no. 4, pp 229\u2013240","key":"471_CR39","DOI":"10.1145\/1080091.1080119"},{"issue":"3","key":"471_CR40","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1145\/1273445.1273454","volume":"37","author":"L Salgarelli","year":"2007","unstructured":"Salgarelli L, Gringoli F, Karagiannis T (2007) Comparing traffic classifiers. ACM SIGCOMM Comput Commun Rev 37(3):65\u201368","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"doi-asserted-by":"crossref","unstructured":"Canini M, Li W, Moore AW, Bolla R (2009) GTVS: boosting the collection of application traffic ground truth. In: Proceedings of the 1st international workshop on traffic monitoring and analysis (TMA\u201909) (Aachen, Germany), Springer Verlag, Heidelberg, Germany, pp 54\u201363","key":"471_CR41","DOI":"10.1007\/978-3-642-01645-5_7"},{"issue":"5","key":"471_CR42","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1145\/1629607.1629610","volume":"39","author":"F Gringoli","year":"2009","unstructured":"Gringoli F, Salgarelli L, Dusi M, Cascarano N, Risso F, Claffy KC (2009) GT: picking up the truth from the ground for Internet traffic. ACM SIGCOMM Comput Commun Rev 39(5):13\u201318","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"doi-asserted-by":"crossref","unstructured":"Szab\u00f3 G, Orincsay D, Malomsoky S, Szab\u00f3 I (2008) On the validation of traffic classification algorithms. In: Proceedings of the passive and active measurement conference (PAM 2008) (Cleveland, OH, USA), LNCS Series, Springer-Verlag, Berlin Heidelberg, vol. 4979, pp 72\u201381","key":"471_CR43","DOI":"10.1007\/978-3-540-79232-1_8"},{"unstructured":"Makhoul J, Kubala F, Schwartz R, Weischedel R (1999) Performance measures for information extraction. In: Proceedings of the DARPA Broadcast News Workshop (Herndon, VA, USA), pp 249\u2013252","key":"471_CR44"},{"unstructured":"Olson DL, Delen D (2008) Advanced data mining techniques, 1st edition, Springer","key":"471_CR45"},{"doi-asserted-by":"crossref","unstructured":"Wang Y (2008) Statistical techniques for network security: modern statistically-based intrusion detection and protection. In: Premier Reference Source, Information Science Reference","key":"471_CR46","DOI":"10.4018\/978-1-59904-708-9"},{"doi-asserted-by":"crossref","unstructured":"Raahemi B, Zhong W, Liu J (2008) Peer-to-peer traffic identification by mining IP layer data streams using concept-adapting very fast decision tree. In: Proceedings of the 20th IEEE international conference on tools with artificial intelligence (ICTAI\u201908), IEEE, vol. 1, pp. 525\u2013532","key":"471_CR47","DOI":"10.1109\/ICTAI.2008.12"},{"unstructured":"Internet Assigned Numbers Authority (IANA), http:\/\/www.iana.org\/assignments\/port-numbers","key":"471_CR48"},{"doi-asserted-by":"crossref","unstructured":"Gomes JV, Inacio PRM, Pereira M, Freire MM, Monteiro PP (2013) Detection and classification of peer-to-peer traffic: A survey. In: ACM Computing Surveys (CSUR), NY, USA, vol. 45, no. 3","key":"471_CR49","DOI":"10.1145\/2480741.2480747"},{"doi-asserted-by":"crossref","unstructured":"Moore AW, Papagiannaki K (2005) Toward the accurate identification of network applications. In: Proceedings of the 6th international conference on Passive and Active Network Measurement (PAM 2005), pp 41\u201354","key":"471_CR50","DOI":"10.1007\/978-3-540-31966-5_4"},{"doi-asserted-by":"crossref","unstructured":"Karagiannis T, Broido A, Brownlee N, Claffy KC, Faloutsos M (2004) Is P2P dying or just hiding?. In: Proceedings of the IEEE global telecommunications conference (GLOBECOM\u201904), vol. 3, pp. 1532\u20131538","key":"471_CR51","DOI":"10.1109\/GLOCOM.2004.1378239"},{"doi-asserted-by":"crossref","unstructured":"Roughan M, Sen S, Spatscheck O, Duffield N (2004) Class-of-service mapping for QoS: A statistical signature-based approach to IP traffic classification. In: Proceedings of the 4th ACM SIGCOMM conference on Internet Measurement (IMC 2004), ACM, New York, NY, USA, pp 135\u2013148","key":"471_CR52","DOI":"10.1145\/1028788.1028805"},{"doi-asserted-by":"crossref","unstructured":"Sen S, Spatscheck O, Wang D (2004) Accurate, scalable in network identification of P2P traffic using application signatures. In: Proceedings of the 13th international conference on World Wide Web (WWW 2004), ACM, New York, NY, USA, pp 512\u2013521","key":"471_CR53","DOI":"10.1145\/988672.988742"},{"doi-asserted-by":"crossref","unstructured":"Karagiannis T, Broido A, Faloutsos M, Claffy KC (2004) Transport layer identification of P2P traffic. In: Proceedings of the 4th ACM SIGCOMM conference on Internet measurement, (IMC 2004), pp 121\u2013134","key":"471_CR54","DOI":"10.1145\/1028788.1028804"},{"doi-asserted-by":"crossref","unstructured":"Wang K, Stolfo SJ (2004) Anomalous payload-based network intrusion detection. In: Lecture Notes in Computer Science, Springer, Berlin, vol. 3224, pp 203\u2013222","key":"471_CR55","DOI":"10.1007\/978-3-540-30143-1_11"},{"issue":"3","key":"471_CR56","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1007\/s12083-012-0172-4","volume":"6","author":"T Song","year":"2013","unstructured":"Song T, Zhou Z (2013) File aware P2P traffic classification: an aid to network management. J Peer-to-Peer Netw Appl (Springer) 6(3):325\u2013339","journal-title":"J Peer-to-Peer Netw Appl (Springer)"},{"unstructured":"Turkett WH, Karode AV, Fulp EW (2008) In-the-dark network traffic classification using support vector machines. In: Proceedings of the 20th National Conference on innovative applications of artificial intelligence (IAAI 2008), AAAI Press, pp 1745\u20131750","key":"471_CR57"},{"doi-asserted-by":"crossref","unstructured":"Freire EP, Ziviani A, Salles RM (2008) Detecting Skype flows in web traffic. In: Proceedings of the IEEE network operations and management symposium (NOMS 2008), IEEE, pp. 89\u201396","key":"471_CR58","DOI":"10.1109\/NOMS.2008.4575121"},{"issue":"4","key":"471_CR59","doi-asserted-by":"crossref","first-page":"204","DOI":"10.1109\/TNSM.2009.041102","volume":"5","author":"EP Freire","year":"2008","unstructured":"Freire EP, Ziviani A, Salles RM (2008) Detecting VoIP calls hidden in web traffic. IEEE Trans Netw Serv Manag 5(4):204\u2013214","journal-title":"IEEE Trans Netw Serv Manag"},{"doi-asserted-by":"crossref","unstructured":"Gomes JVP, In\u00e1cio PRM, Freire MM, Pereira M, Monteiro PP (2008) Analysis of peer-to-peer traffic using a behavioural method based on entropy. In: Proceedings of the 27th IEEE International Performance Computing and Communications Conference (IPCCC 2008), IEEE Computer Society Press, Austin, Texas, pp. 201\u2013208","key":"471_CR60","DOI":"10.1109\/PCCC.2008.4745138"},{"issue":"3","key":"471_CR61","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/S1005-8885(10)60069-6","volume":"18","author":"M Sun","year":"2011","unstructured":"Sun M, Chen J (2011) Research of the traffic characteristics for the real time online traffic classification. J China Univ Posts Telecommun (Elsevier) 18(3):92\u201398","journal-title":"J China Univ Posts Telecommun (Elsevier)"},{"unstructured":"Moore AW, Zuev D (2006) Discriminators for use in flow-based classification. In: Proceedings of the 20th BCS HCI Group Conference (HCI\u201906), London, UK, Sep 11\u201315","key":"471_CR62"},{"issue":"2","key":"471_CR63","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1145\/1129582.1129589","volume":"36","author":"L Bernaille","year":"2006","unstructured":"Bernaille L, Teixeira R, Akodkenou I, Soule A, Salamatian K (2006) Traffic classification on the fly. ACM SIGCOMM Comput Commun Rev 36(2):23\u201326","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"issue":"5","key":"471_CR64","doi-asserted-by":"crossref","first-page":"391","DOI":"10.1631\/FITEE.1400267","volume":"16","author":"J He","year":"2015","unstructured":"He J, Yang Y, Qiao Y, Deng W (2015) Fine-grained P2P traffic classification by simply counting flows. Front Inf Technol Electron Eng 16(5):391\u2013403","journal-title":"Front Inf Technol Electron Eng"},{"unstructured":"Yang Kai, Wang B, Zhang Z (2013) A method of identifying P2P live streaming based on union features. In 4th IEEE International Conference on Software Engineering and Service Science (ICSESS), Beijing, pp. 426\u2013429","key":"471_CR65"},{"issue":"2","key":"471_CR66","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1007\/s12083-015-0350-2","volume":"9","author":"T Qin","year":"2015","unstructured":"Qin T, Wang L, Zhao D, Zhu M (2015) CUFTI: methods for core users finding and traffic identification in P2P systems. J Peer-to-Peer Netw Appl (Springer) 9(2):424\u2013435","journal-title":"J Peer-to-Peer Netw Appl (Springer)"},{"unstructured":"Zhang Q, Ma Y, Zhang P, Wang J, Li X (2004) Netflow Based P2P detection in UDP traffic. In IEEE 5th International Conference on Intelligent Control and Information Processing (ICICIP), Dalian, pp. 250\u2013254","key":"471_CR67"},{"issue":"7","key":"471_CR68","doi-asserted-by":"crossref","first-page":"36","DOI":"10.4304\/jcm.1.7.36-46","volume":"1","author":"M Per\u00e9nyi","year":"2006","unstructured":"Per\u00e9nyi M, Dang TD, Gefferth A, Moln\u00e1r S (2006) Identification and analysis of peer-to-peer traffic. J Commun 1(7):36\u201346","journal-title":"J Commun"},{"doi-asserted-by":"crossref","unstructured":"John W, Tafvelin S (2008) Heuristics to classify Internet backbone traffic based on connection patterns. In: Proceedings of the international conference on information networking (ICOIN 2008), IEEE, pp. 1\u20135","key":"471_CR69","DOI":"10.1109\/ICOIN.2008.4472818"},{"doi-asserted-by":"crossref","unstructured":"Hong W (2011) A novel method for P2P traffic identification. In: Procedia Engineering (Elsevier), vol. 23, pp. 204\u2013209","key":"471_CR70","DOI":"10.1016\/j.proeng.2011.11.2490"},{"unstructured":"Reddy JM, Hota C (2015) Heuristic-based real-time P2P traffic identification. In IEEE international conference on emerging information technology and engineering solutions (EITES), Pune, pp. 38\u201343","key":"471_CR71"},{"doi-asserted-by":"crossref","unstructured":"Bashir A, Huang C, Nandy B, Seddigh N (2013) Classifying P2P activity in netflow records: a case study on BitTorrent. In IEEE International Conference on Communications (ICC), Budapest, pp. 3018\u20133023","key":"471_CR72","DOI":"10.1109\/ICC.2013.6655003"},{"doi-asserted-by":"crossref","unstructured":"Mcgregor A, Hall M, Lorier P, Brunskill J (2004) Flow clustering using machine learning techniques. In: Proceedings of the passive and active measurement workshop (PAM 2004) (Antibes Juanles- Pins, France). LNCS Series, Springer-Verlag, Berlin Heidelberg, vol. 3015, pp 205\u2013214","key":"471_CR73","DOI":"10.1007\/978-3-540-24668-8_21"},{"issue":"1","key":"471_CR74","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1145\/1071690.1064220","volume":"33","author":"AW Moore","year":"2005","unstructured":"Moore AW, Zuev D (2005) Internet traffic classification using bayesian analysis techniques. ACM SIGMETRICS Perform Eval Rev 33(1):50\u201360","journal-title":"ACM SIGMETRICS Perform Eval Rev"},{"doi-asserted-by":"crossref","unstructured":"Branch PA, Heyde A, Armitage GJ (2009) Rapid identification of Skype traffic flows. In: Proceedings of the 18th international workshop on network and operating system support for digital audio and video (NOSSDAV\u201909), ACM, NY, USA, pp 91\u201396","key":"471_CR75","DOI":"10.1145\/1542245.1542266"},{"doi-asserted-by":"crossref","unstructured":"Schmidt SEG, Soysal M (2006) An intrusion detection based approach for the scalable detection of P2P traffic in the national academic backbone network. In: Proceedings of the International Symposium on Computer Networks (ISCN 2006), IEEE, pp. 128\u2013133","key":"471_CR76","DOI":"10.1109\/ISCN.2006.1662521"},{"doi-asserted-by":"crossref","unstructured":"Cao J, Chen A, Widjaja I, Zhou N (2008) Online identification of applications using statistical behavior analysis. In: Proceedings of the IEEE Global Telecommunications Conference (GLOBECOM 2008), IEEE, pp. 1\u20136","key":"471_CR77","DOI":"10.1109\/GLOCOM.2008.ECP.287"},{"doi-asserted-by":"crossref","unstructured":"Angevine D, Zincir-heywood AN (2008) A preliminary investigation of Skype traffic classification using a minimalist feature set. In: Proceedings of the 3rd International Conference on Availability, Reliability and Security (ARES 08), IEEE Computer Society Press, pp. 1075\u20131079","key":"471_CR78","DOI":"10.1109\/ARES.2008.158"},{"doi-asserted-by":"crossref","unstructured":"Wang Y-H, Gau V, Bosaw T, Hwang J-N, Lippman A, Liebennan D, Wu I-C (2008) Generalization performance analysis of flow-based peer-to-peer traffic identification. In: Proceedings of the IEEE Workshop on Machine Learning for Signal Processing (MLSP 2008), IEEE, pp 267\u2013272","key":"471_CR79","DOI":"10.1109\/MLSP.2008.4685491"},{"doi-asserted-by":"crossref","unstructured":"Dainotti A, de Donato W, Pescape A, Rossi PS (2008) Classification of network traffic via packet-level hidden markov models. In: Proceedings of the IEEE Global Telecommunications Conference (GLOBECOM 2008), IEEE, pp. 1\u20135","key":"471_CR80","DOI":"10.1109\/GLOCOM.2008.ECP.412"},{"doi-asserted-by":"crossref","unstructured":"Valenti S, Rossi D, Meo M, Mellia M, Bermolen P (2009) Accurate, fine-grained classification of P2P-TV applications by simply counting packets. In: Proceedings of the 1st international workshop on traffic monitoring and analysis (TMA\u201909), LNCS Series, vol. 5537. Springer-Verlag, Berlin, Heidelberg, pp. 84\u201392","key":"471_CR81","DOI":"10.1007\/978-3-642-01645-5_10"},{"doi-asserted-by":"crossref","unstructured":"Liu H, Feng W, Huang Y, Li X (2007) A peer-to-peer traffic identification method using machine learning. In: Proceedings of the international conference on networking, architecture, and storage (NAS 2007), IEEE, pp. 155\u2013160","key":"471_CR82","DOI":"10.1109\/NAS.2007.6"},{"doi-asserted-by":"crossref","unstructured":"Raahemi B, Kouznetsov A, Hayajneh A, Rabinovitch P (2008) Classification of peer-to-peer traffic using incremental neural networks (fuzzy ARTMAP). In: Proceedings of the Canadian conference on electrical and computer engineering (CCECE 2008), IEEE, pp. 719\u2013724","key":"471_CR83","DOI":"10.1109\/CCECE.2008.4564629"},{"doi-asserted-by":"crossref","unstructured":"Hu Y, Chiu D-M, Lui JCS (2008) Application identification based on network behavioral profiles. In: Proceedings of the 16th International Workshop on Quality of Service (IWQoS 2008), IEEE, pp. 219\u2013228","key":"471_CR84","DOI":"10.1109\/IWQOS.2008.31"},{"issue":"6","key":"471_CR85","doi-asserted-by":"crossref","first-page":"849","DOI":"10.1016\/j.comnet.2008.11.005","volume":"53","author":"Y Hu","year":"2009","unstructured":"Hu Y, Chiu D-M, Lui JCS (2009) Profiling and identification of P2P traffic. Comput Netw 53(6):849\u2013863","journal-title":"Comput Netw"},{"doi-asserted-by":"crossref","unstructured":"Liu S-M, Sun Z-X (2014) Active learning for P2P traffic identification. In: Journal of Peer-to-Peer Networking and Applications (Springer)","key":"471_CR86","DOI":"10.1007\/s12083-014-0281-3"},{"doi-asserted-by":"crossref","unstructured":"Moore AW, Zuev D (2005) Internet traffic classification using Bayesian analysis techniques. In: Proceedings of the 2005 ACM SIGMETRICS international conference on Measurement and modeling of computer systems, ACM, NY, USA, pp. 50\u201360","key":"471_CR87","DOI":"10.1145\/1064212.1064220"},{"doi-asserted-by":"crossref","unstructured":"Jiang D, Tao L (2013) P2P traffic identification research based on the SVM. In: 22nd Wireless and Optical Communication Conference (WOCC, 2013), IEEE, Chongqing, China, pp. 683\u2013686","key":"471_CR88","DOI":"10.1109\/WOCC.2013.6676461"},{"doi-asserted-by":"crossref","unstructured":"Gong J, Wang W, Wang P, Sun Z (2014) P2P traffic identification method based on an improvement incremental SVM learning algorithm. In: Proceeding of international symposium on wireless personal multimedia communications (WPMC 2014), IEEE, Sydney, NSW, pp. 174\u2013179","key":"471_CR89","DOI":"10.1109\/WPMC.2014.7014812"},{"doi-asserted-by":"crossref","unstructured":"Deng S, Luo J, Liu Y, Wang X, Yang J (2014) Ensemble learning model for P2P traffic identification. In: 11th international conference on fuzzy systems and knowledge discovery (FSKD 2014), IEEE, Xiamen, pp. 436\u2013440","key":"471_CR90","DOI":"10.1109\/FSKD.2014.6980874"},{"issue":"11","key":"471_CR91","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1109\/CC.2013.6674209","volume":"10","author":"H Jie","year":"2013","unstructured":"Jie H, Yuexiang Y, Yong Q, Chuan T (2013) Accurate classification of P2P traffic by clustering flows. Commun China IEEE 10(11):42\u201351","journal-title":"Commun China IEEE"},{"doi-asserted-by":"crossref","unstructured":"Bozdogan C, Gokcen Y, Zincir I (2015) A preliminary investigation on the identification of peer to peer network applications. In Proceedings of the Companion Publication of the 2015 Annual Conference on Genetic and Evolutionary Computation, ACM, NY, USA, pp. 883\u2013888","key":"471_CR92","DOI":"10.1145\/2739482.2768432"},{"unstructured":"Dedinski I, Meer HD, Han L, Mathy L, Pezaros DP, Sventek JS, Xiaoying Z (2005) Cross-layer peer-to-peer traffic identification and optimization based on active networking. In: Proceedings of the 7th annual international working conference on active and programmable networks (IWAN 2005) (Sophia Antipolis, France, Nov.). Springer-Verlag, Berlin Heidelberg, pp. 13\u201327","key":"471_CR93"},{"doi-asserted-by":"crossref","unstructured":"Adami D, Callegari C, Giordano S, Pagano M, Pepe T (2009) A real-time algorithm for Skype traffic detection and classification. In: Proceedings of the 9th international conference on next generation wired\/wireless networking (NEW2AN\u201909) (St. Petersburg, Russia, Sept.), LNCS Series, vol. 5764. Springer-Verlag, Berlin Heidelberg, pp. 168\u2013179","key":"471_CR94","DOI":"10.1007\/978-3-642-04190-7_16"},{"issue":"3","key":"471_CR95","first-page":"64","volume":"13","author":"J Yan","year":"2013","unstructured":"Yan J, Wu Z, Luo H, Zhang S (2013) P2P traffic identification based on host and flow behaviour characteristics. Cybern Inf Technol 13(3):64\u201376","journal-title":"Cybern Inf Technol"},{"issue":"9","key":"471_CR96","doi-asserted-by":"crossref","first-page":"1815","DOI":"10.1007\/s00500-014-1253-5","volume":"18","author":"W Ye","year":"2014","unstructured":"Ye W, Cho K (2014) Hybrid P2P traffic classification with heuristic rules and machine learning. J Soft Comput, Springer, Berlin Heidelberg 18(9):1815\u20131827","journal-title":"J Soft Comput, Springer, Berlin Heidelberg"},{"unstructured":"Ye W, Cho K (2015) P2P and P2P botnet traffic classification in two stages. In Journal of Soft Computing, Springer Berlin Heidelberg, pp. 1\u201312","key":"471_CR97"},{"doi-asserted-by":"crossref","unstructured":"Wang D, Zhang L, Yuan Z, Xue Y, Dong Y (2014) Characterizing application behaviors for classifying P2P traffic. In: International Conference on Computing, Networking and Communications (ICNC 2014), IEEE, Honolulu, HI, pp. 21\u201325","key":"471_CR98","DOI":"10.1109\/ICCNC.2014.6785298"},{"issue":"1","key":"471_CR99","first-page":"85","volume":"7","author":"Z Yang","year":"2012","unstructured":"Yang Z, Li L, Ji Q, Zhu Y (2012) Cocktail method for BitTorrent traffic identification in real time. J Comput 7(1):85\u201395","journal-title":"J Comput"},{"doi-asserted-by":"crossref","unstructured":"Korczynski M, Duda A (2014) Markov chain fingerprinting to classify encrypted traffic. In: Proceedings of 2014 IEEE, INFOCOM, Toronto, pp. 781\u2013789","key":"471_CR100","DOI":"10.1109\/INFOCOM.2014.6848005"},{"issue":"1","key":"471_CR101","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1016\/j.jksuci.2014.03.013","volume":"27","author":"R Alshammari","year":"2015","unstructured":"Alshammari R, Zincir-Heywood AN (2015) Identification of VoIP encrypted traffic using a machine learning approach. J King Saud Univ Comput Inf Sci NY, USA 27(1):77\u201392","journal-title":"J King Saud Univ Comput Inf Sci NY, USA"},{"doi-asserted-by":"crossref","unstructured":"Kumano Y, Ata S, Nakamura N, Nakahira Y, Oka I (2014) Towards real-time processing for application identification of encrypted traffic. In: International conference on computing, networking and communications (ICNC), Honolulu, pp. 136\u2013140","key":"471_CR102","DOI":"10.1109\/ICCNC.2014.6785319"},{"doi-asserted-by":"crossref","unstructured":"Wang X, Yang Y, He J (2014) Identifying P2P network activities on encrypted traffic. In: 13th IEEE international conference on trust, security and privacy in computing and communications (TrustCom), Beijing, pp. 893\u2013899","key":"471_CR103","DOI":"10.1109\/TrustCom.2014.117"},{"issue":"1","key":"471_CR104","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1007\/s11235-013-9690-5","volume":"53","author":"Y Du","year":"2013","unstructured":"Du Y, Zhang R (2013) Design of a method for encrypted P2P traffic identification using K-means algorithm. J Telecommun Syst (Springer) 53(1):163\u2013168","journal-title":"J Telecommun Syst (Springer)"},{"doi-asserted-by":"crossref","unstructured":"Datta J, Kataria N, Hubballi N (2015) Network traffic classification in encrypted environment: a case study of google hangout. In 21st IEEE National Conference on Communications (NCC), Mumbai, pp. 1\u20136","key":"471_CR105","DOI":"10.1109\/NCC.2015.7084879"},{"doi-asserted-by":"crossref","unstructured":"Saroiu S, Gummadi KP, Dunn RJ, Gribble SD, Levy HM (2002) An analysis of Internet content delivery systems. In: Proceedings of the 5th symposium on operating systems design and implementation (OSDI\u201902), ACM, New York, NY, USA, vol. 36, pp 315\u2013327","key":"471_CR106","DOI":"10.1145\/844128.844158"},{"unstructured":"Leibowitz N, Bergman A, Ben-shaul R, Shavit A (2002) Are file swapping networks cacheable? Characterizing P2P traffic. In: Proceedings of the 7th international workshop on web content caching and distribution (WCW)","key":"471_CR107"},{"unstructured":"Gerber A, Houle J, Nguyen H, Roughan M, Sen S (2003) P2P, the gorilla in the cable. In: Proceedings of the national cable & telecommunications association (NCTA), pp 8\u201311","key":"471_CR108"},{"doi-asserted-by":"crossref","unstructured":"Spognardi A, Lucarelli A, Pietro RD (2005) A methodology for P2P file-sharing traffic detection. In: Proceedings of the 2nd international workshop on hot topics in peer-to-peer systems (HOT-P2P\u201905), IEEE Computer Society, Washington, DC, USA, pp. 52\u201361","key":"471_CR109","DOI":"10.1109\/HOT-P2P.2005.2"},{"doi-asserted-by":"crossref","unstructured":"Bin L, Zhi-Tang L, Hao T (2007) A methodology for P2P traffic measurement using application signature work-in-progress. In: Proceedings of the 2nd international conference on scalable information systems (InfoScale\u201907), ICST, Brussels, Belgium","key":"471_CR110","DOI":"10.4108\/infoscale.2007.905"},{"doi-asserted-by":"crossref","unstructured":"Dewes C, Wichmann A, Feldmann A (2003) An analysis of Internet chat systems. In: Proceedings of the ACM SIGCOMM internet measurement conference (IMC 2003), ACM, New York, NY, USA, pp. 51\u201364","key":"471_CR111","DOI":"10.1145\/948205.948214"},{"unstructured":"Guo Z, Qiu Z (2008) Identification peer-to-peer traffic for high speed networks using packet sampling and application signatures. In: Proceedings of the 9th international conference on signal processing (ICSP 2008), IEEE, pp. 2013\u20132019","key":"471_CR112"},{"doi-asserted-by":"crossref","unstructured":"Cascarano N, Ciminiera L, Risso F (2010) Improving cost and accuracy of DPI traffic classifiers. In: Proceedings of the 2010 ACM symposium on applied computing (SAC 2010), ACM, New York, NY, USA, pp. 641\u2013646","key":"471_CR113","DOI":"10.1145\/1774088.1774223"},{"doi-asserted-by":"crossref","unstructured":"Carvalho DA, Pereira M, Freire MM (2009) Towards the detection of encrypted BitTorrent traffic through deep packet inspection. In: Proceedings of the international conference on security technology (SecTech 2009), communications in computer and information science series, Springer-Verlag, Berlin Heidelberg, vol. 58, pp. 265\u2013272","key":"471_CR114","DOI":"10.1007\/978-3-642-10847-1_33"},{"unstructured":"Carvalho DA, Pereira M, Freire MM (2009) Detection of peer-to-peer TV traffic through deep packet inspection. In: Acta da 9a Conference sobre Redes de Computadores (Oeiras, Portugal, Oct.). INESC-ID and Instituto Superior T\u00e9cnico, 6","key":"471_CR115"},{"doi-asserted-by":"crossref","unstructured":"Freire MM, Carvalho DA, Pereira M (2009) Detection of encrypted traffic in eDonkey network through application signatures. In: Proceedings of the 1st international conference on advances in P2P systems (AP2PS 2009), IEEE Computer Society Press, Los Alamitos, CA, USA, pp.174\u2013179","key":"471_CR116","DOI":"10.1109\/AP2PS.2009.35"},{"doi-asserted-by":"crossref","unstructured":"Park B.-C, Won YJ, Kim M.-S, Hong JW (2008) Towards automated application signature generation for traffic identification. In: Proceedings of the IEEE\/IFIP Network Operations and Management Symposium (NOMS 2008), IEEE, pp. 160\u2013167","key":"471_CR117","DOI":"10.1109\/NOMS.2008.4575130"}],"container-title":["Peer-to-Peer Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s12083-016-0471-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-016-0471-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-016-0471-2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s12083-016-0471-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,3]],"date-time":"2025-06-03T22:09:28Z","timestamp":1748988568000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s12083-016-0471-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,6,18]]},"references-count":117,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2017,9]]}},"alternative-id":["471"],"URL":"https:\/\/doi.org\/10.1007\/s12083-016-0471-2","relation":{},"ISSN":["1936-6442","1936-6450"],"issn-type":[{"type":"print","value":"1936-6442"},{"type":"electronic","value":"1936-6450"}],"subject":[],"published":{"date-parts":[[2016,6,18]]}}}