Technology Review - Published By MIT
Advertisement

Sniffing Out Illicit BitTorrent Files

A new tool promises to detect illegal files without slowing network traffic.

By Duncan Graham-Rowe

Thursday, February 12, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

A new technique has been developed for detecting and tracking illegal content transferred using the BitTorrent file-trading protocol. According to its creators, the approach can monitor networks without interrupting the flow of data and provides investigators with hard evidence of illicit file transfers.

Credit: Technology Review

Contraband files might include pirated movies, music, or software, and even child pornography. When the tool detects such a file, it keeps a record of the network addresses involved for later analysis, says Major Karl Schrader, who led the work at the Air Force Institute of Technology, in Kettering, OH.

The use of peer-to-peer (P2P) software and of the BitTorrent protocol in particular have increased steadily over recent years. In fact, for many Internet service providers (ISPs), the vast majority of Internet traffic now consists of P2P transfers.

ISPs are generally only interested in detecting this type of traffic in order to control, or "throttle," it and free up bandwidth for other uses. However, this approach reveals nothing about the contents of each transfer, says Schrader. A handful of network-monitoring tools can identify specific BitTorrent files, but the process is generally slow, since the contents of each file have to be examined. The time that this takes also increases exponentially as the number of files that need to be scanned grows.

"Our system differs in that it is completely passive, meaning that it does not change any information entering or leaving a network," says Schrader. It works, he says, by first spotting files that bare the hallmark of the BitTorrent protocol by examining the first 32 bits of the files' header data. Then the system looks at the files' hash, a unique identifying code used to coordinate the simultaneous download of hundreds of file fragments by different users. If a hash matches any stored in a database of prohibited hashes, then the system will make a record of the transfer and store the network addresses involved.

Story continues below


"I'm convinced that the solution works and that it will be quite cheap, as it is very specialized," says Hendrik Schulze, chief technology officer of Ipoque, a network analysis company based in Leipzig, Germany. More generalized solutions that try to monitor for a wide range of file types may be more flexible, he says, but they will also be more expensive.

One reason why the new technique is so fast is that the apparatus required consists of a specially configured field programmable gate array (FPGA) chip and a flash-memory card that stores a log of the illicit activity.

Comments

  • Encrypted BitTorrent is easy
    Using encrypted BitTorrent is super easy, it takes just to click on another .torrent file, or installing another BitTorrent client that supports encrypted activity. Using such encryption is exactly just as easy for the average user as installing a new Napster, Kazzaa, Emule or BitTorrent software on their computer.

    Analysing hashes, measuring traffic and all that could be very useful though. But it shouldn't be to stop or to punish children that download pirated stuff, it should be about measuring popularity of stuff to then pay the artists from a music tax according to the popularity and the quality of the content.

    Publishers, distributors, record labels, movie studios and TV channels, all of these intermediaries have become completely irrelevant and useless with the advent of the Internet which quite obviously makes it possible for the artists to distribute their works directly to the public. Politicians need to recognize that fact and a new law should block those useless intermediaries from corrupting artists and stop them from trying to keep controlling the media. The new media is out of their control.

    $5 per citizen per month will pay for many more artists and much better art.

    Charbax
    02/12/2009
    Posts:1
    Avg Rating:
    3/5
    • Re: Encrypted BitTorrent is easy
      I don't want to pay a tax on media that the public consumes. A lot of what is popular, I don't find entertaining, why should I help pay for American Idol or The Biggest Loser?  Pretty much the only media I watch comes from Japan or China.

      enantiomer20...
      02/12/2009
      Posts:50
      Avg Rating:
      3/5
    • Re: Encrypted BitTorrent is easy
      Your point is that encrypted traffic can't be analyzed this way.

      But the article isn't talking about analyzing bittorrent traffic, its talking about analyzing the downloading of *.bittorrent files.

      I'm fairly certain the author doesn't understand the difference.

      bugme
      02/15/2009
      Posts:29
      Avg Rating:
      3/5

This discussion has been moved to our discussions forum.

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.