摘要
针对单独的深度数据包检测(Deep packet inspection,DPI)技术无法识别加密报文,以及基于流量特征识别方法对流量检测的模糊性等问题,采用DPI和基于流量特征相结合的方法来对Ares协议进行精确的识别,以提高对Ares协议的识别效果,实验表明准确率可以达到97%以上。
In this paper we find a method to accurately identify the Ares protocol by using DPI combined with DFI technology. In this way, it not only overcome the shortage of DPI technology which can' t identify the encrypted flows and data flows, but also solve the imprecision of the DFI technology, so that those couples can work smoothly, and make up with each other, and also improve the identification effect, the accuracy rate can up to 97%.
出处
《信息化研究》
2012年第1期25-29,共5页
INFORMATIZATION RESEARCH
基金
国家自然科学基金(60973139
61170065
61171053)
江苏省科技支撑计划(工业)项目(BE2010197
BE 2010198
BE2011844)
江苏省高校自然科学基础研究项目(10KJB520013
10KJB520014)
关键词
点对点
协议识别
深度数据包检测技术
神经网络
流量特征
peer-to-peer
protocol identification
deep packet inspection
neural network
traffic characteristic