Abstract
There are more and more P2P applications in the Internet, with or without encrypted content. The P2P applications can be classified into three categories: file sharing (BT, eMule), VoIP (Skype, MSN), and Video streaming (PPStream, PPLive). By observing the common communication nature among the peers, this paper proposes a simple but efficient way to identify the P2P traffic by the DNS query behavior. Experimental results illustrate that the proposed mechanism is able to accurately identify if a host is using data/voice/video-based P2P traffic, even the packet content is encrypted. The proposed mechanism is also capable of detecting future unknown P2P applications as long as they perform the common P2P behaviors. ©2009 IEEE.