期刊文献+

A Real-Time TCP Stream Reassembly Mechanism in High-Speed Network 被引量:3

A Real-Time TCP Stream Reassembly Mechanism in High-Speed Network
下载PDF
导出
摘要 With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network. With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network.
出处 《Journal of Southwest Jiaotong University(English Edition)》 2009年第3期185-191,共7页 西南交通大学学报(英文版)
基金 National High-Tech Research and Development Program of China (863 Program) (No.2007AA01Z309)
关键词 TCP stream reassembly High-speed network Real-time property Reassembly policy TCP stream reassembly High-speed network Real-time property Reassembly policy
  • 相关文献

参考文献1

二级参考文献7

  • 1NorthcuttS.网络入侵检测分析员手册[M].北京:人民邮电出版社,2000..
  • 2TaylorED 王虎 邓宏涛 刘志刚译.TCP/IP使用详解[M].北京:机械工业出版社,1999..
  • 3BuyyaR.高性能集群计算:编程与应用(第2卷)[M].北京:电子工业出版社,2001..
  • 4Anderson D, Frivold T, Valdes A. Next-generation Intrusion-Detection Expert System (NIDES): A Summary[R]. SRL- CSL-95-07, SRI International, Menlo Park, CA, 1995.
  • 5Handley M, Kreibich C, Paxson V. Network Intrusion Detection:Evasion, Traffic Normalization, and End-to-End Protocol Semantics [C]. In: Proceedings of the 10^th USENIX Security Symposium,Washington D C, 2001-08:115-131.
  • 6Zhao Xiaoling, Sun Jizhou. A Parallel Scheme for IDS [C]. In:Proceedings of the Second International Conference on Machine Learning and Cybernetics (ICMLC), 2003-05:2379- 2383.
  • 7蒋建春,马恒太,任党恩,卿斯汉.网络安全入侵检测:研究综述[J].软件学报,2000,11(11):1460-1466. 被引量:369

同被引文献26

  • 1杨宏宇,赵晓玲.应用层并行重组在NIDS中的设计与实现[J].吉林大学学报(理学版),2006,44(4):575-582. 被引量:4
  • 2邓子宽,范明钰,王光卫,朱大勇.Snort入侵检测系统中TCP流重组的研究[J].信息安全与通信保密,2007,29(2):65-67. 被引量:6
  • 3Ethan Blanton, Mark Allman. On making TCP more robust to packet reordering[ J ]. ACM, 2002,32(1) : 20 - 30.
  • 4Charles M Kozierok.TCP/IP指南,卷1:底层核心协议[M].北京:人民邮电出版社,2008:511-587.
  • 5Richard ,TCP/IP详解卷1:协议[M].北京:机械工业出版社,2000:17-18.
  • 6Ptacek T, Newsham T. Insertion, evasion, and deni- al of service., eluding network intrusion detection [R]//Secure Networks Inc. [s. I. ]:[s. n. ], 1998.
  • 7Dharmapurikar S, Paxson V. Robust TCP stream re- assembly in the presence of adversaries [C] ff Balti- more,America, Proceedings of the 14th USENIX Se- curity Symposium. Baltimore, America: USENIX Symposium, 2005.
  • 8Necker M, Contis D, Schimmel D. TCP-Stream re- assembly and state tracking in hardware [C]//10th Annual IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM' 02), Calior-nia America : FCCM' 02, 2002.
  • 9Ruan Y, Yang W B, Chen M Y, etal,Robust TCP reassembly with a Hardware-Based solution for back- bone traffic [C] // Proeeedings of the 2010 IEEE Fifth International Conference on Networking, Architec- ture, and Storage, p. 439-447, July 15-17. Maeau China; IEEE, 2010.
  • 10赵晓玲,孙济洲.应用层协议并行重组算法的设计与实现[D].天津:天津大学,2004.

引证文献3

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部