Journal of Xidian University

Previous Articles     Next Articles

Passive browser identification based on the packet length

LIU Changjiang;WAN Jian;HAN Jiesi;WEI Qiang   

  1. (National Key Lab. of Science and Technology on Blind Signal Processing, Chengdu 610041, China)
  • Received:2016-09-22 Online:2017-12-20 Published:2018-01-18

Abstract:

The browser, as the most frequently used network application software, is an important target of hackers. For network administrators, mastering the browsers used by network users can help them to discover the possible vulnerabilities in the host computers and take defensive measures expediently. In this paper, we propose a passive browser identification method by requesting the packet length. We make use of the difference in requesting the packet length when using different browsers to request the web content, and then achieve the browser identification by the clustering algorithm. The experiment shows that the recognition rate of the five most common browsers can reach more than 90% in this way, and the time stability of the fingerprinting is also confirmed. This method does not increase the network traffic or interfere with the normal operation of the network, and it can identify web browsers under the condition of both non-encryption and encryption.

Key words: browser, passive identification, packet length, classification, feature stability