期刊文献+

基于特征串的应用层协议识别 被引量:43

Identification of Application-Level Protocols Using Characteristic
下载PDF
导出
摘要 随着各种P2P协议的广泛应用以及逃避防火墙检测的需要,传统的基于常用端口识别应用层协议的方法已经出现问题。文章通过分析可用的文档和实际报文TRACE,分别为七种应用层协议找出其实际交互过程中必须出现且出现频率最高的固定字段,并将这些固定字段作为协议的特征串来识别这七种协议。实验结果表明,相较于端口方法,使用特征串方法识别这七种应用层协议具有更高的准确性,并且时间消耗的增长不会超过2%。 Along with the emergence of many P2P protocols and the need of circurhventing firewalls,traditional methods of application-level protocol identification such as using default server port become more and more inaccurate.The characteristic for each of seven application-level protocols is defined by analyzing some available documentations and packet-level traces in this paper.The characteristic of a protocol is a necessary part of actual communication,and it is more frequent to be used than any other necessary parts.These characteristics then are utilized to identify the seven protocols.The measurements show that the approach has higher accuracy than traditional port-based approach,and the time consumption increment do not exceed 2%.
出处 《计算机工程与应用》 CSCD 北大核心 2006年第24期16-19,86,共5页 Computer Engineering and Applications
基金 国家973重点基础研究发展规划项目资助(编号:2003CB314804) 教育部科学技术重点研究项目(编号:105084) 江苏省网络与信息安全重点实验室资助(编号:BM2003201)
关键词 网络流量 应用层协议识别 特征串 network traffic,application-level protocol identification,characteristic string
  • 相关文献

参考文献13

  • 1Subhabrata Sen,Jia Wang.Analyzing Peer-to-Peer Traffic across Large Networks[C].In:IEEE/ACM Transactions on Networking,NJ:IEEE Press,2004:219~232
  • 2IANA[S].http://www.iana.org/assignments/port-numbers
  • 3Myung-Sup Kim,Young J Won,James Won-Ki Hong.Application-Level Traffic Monitoring and an Analysis on IP Networks[J].ETRI Journal,2005;27(11):22~42
  • 4Subhabrata Sen,Oliver Spatscheck,Dongmei Wang.Accurate,Scalable In-Network Identification of P2P Traffic Using Application Signatures[C].In:Proceedings of the 13th international conference on World Wide Web,NY:ACM Press,2004:512~521
  • 5Luca Deri,NETikos,SPA.Improving passive packet capture:beyond device polling.http://jake.unipi.it/Ring.pdf,2004-10/2005-11
  • 6BitTorrent.http://www.bittorrent.com/protocol.html
  • 7Yoram Kulbak,Danny Bickson.The eMule Protocol Specification.http://ftp.citkit.ru/pub/sourceforge/e/em/emule/protocol_guide.pdf,2005 -01/2005-11
  • 8MSN Messenger Protocol.http://www.hypothetic.org/docs/msn/index.php
  • 9R Movva,W Lai.MSN Messenger Service 1.0 Protocol.http://www.hypothetic.org/docs/msn/sitev1/index.php,2003-09-/2005-11
  • 10Simple Mail Transfer Protocol[S].RFC 2821

同被引文献299

引证文献43

二级引证文献94

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部