期刊文献+

基于关键字的单协议分类

Classification of Single Protocol Based on Keywords
下载PDF
导出
摘要 网络协议是网络通信中一系列标准的集合,未知协议的识别和分析对网络监管、保障网络安全具有重大意义。协议识别技术多种多样,但大都不适用于二进制的协议识别。在此针对现有的协议识别技术的局限性,提出了一种在双方单协议通信环境下的多种类型二进制数据帧的协议识别方法。该方法首先利用n-gram技术对数据帧进行分割,然后利用无监督的特征选择算法提取特征串集合,从而利用聚类算法实现协议消息的识别。最后在ICMP上对该方法进行评估,消息识别的准确率和召回率均可达到90%以上。 Network protocols are sets of standards for certain network communications. The protocol identification and analysis have great significance for network management and security. Although there are all kinds of protocol identifi- cation technology,most of them are not suitable for the binary protocol identification. To address this issue, the paper proposed a novel method of protocol identification which can classify the same protocol into several messages in the en- vironment of single protocol communication. This method utilizes n-gram to segment the data frames and then extracts the set of keywords using unsupervised feature selection algorithm. At last,it implements the identification of different type of messages using clustering algorithm. Finally the method was evaluated on ICMP. The results show that the rate of precision and recall can both reach more than 90%.
作者 郑杰 李建平
出处 《计算机科学》 CSCD 北大核心 2015年第10期60-64,共5页 Computer Science
基金 中国工程物理研究院科技发展基金(2012A0403021) NSAF联合基金(U1230106) 国家信息安全发展计划(2013F098)资助
关键词 协议识别 单协议 无监督 特征选择 聚类算法 Protocol identification,Single protocol,Unsupervised,Feature selection,Clustering algorithm
  • 相关文献

参考文献19

  • 1牟乔.准确高效的应用层协议分析识别方法[J].计算机工程与科学,2010,32(8):39-45. 被引量:8
  • 2IANA [OL]. http://www.iana.org/assignments/port一num-bers.
  • 3Liu R T,Huang N F,Chen C H,et al. A fast string-matching al-gorithm for network processor-based intrusion detection system[J]. ACM Transactions on Embedded Computing Systems,2004.3(3):614-633.
  • 4IANA. Internet Assigned Numbers Authority [OL]. http;//www. iana. org/assignments/port-numbers.
  • 5Kim M S’Won Y J, Hong J W K. Application-level traffic moni-toring and an analysis on IP networks[J]. ETRI Journal.2005,27(1):22-42.
  • 6Chen C C, Wang S D. An efficient multicharacter transitionstring-matching engine based on the Aho-Corasick Algorithm[J]. ACM transactions on architecture and code optimization,2013,10(4):1-22.
  • 7Wright C,Monrose F, Masson G M. HMM profiles for networktraffic classification[C] // Proceedings of the 2004 ACM Work-shop on Visualization and Data Mining for Computer Security.New York,USA, ACM,2004:9-15.
  • 8Wright C,Monrose F,Masson G M. Towards better protocolidentification using profile HMMs: JHU-SPAR051201 [R].2005-.325-328.
  • 9Bernaille L,Teixera R, Akodkenou I,et al. Traffic classificationon the fly[J]. ACM SIGCOMM Computer Communication Re-view,2006,36(2)-23-26.
  • 10Zander S,Nguyen T. Armitage G. Self-learning IP traffic classi-fication based on statistical flow characteristics [M] // Passiveand Active Network Measurement. Heidelberg, Germany :Springer, 2005.

二级参考文献6

  • 1Corbet J, Rubini A, Kroah-Hartman G. Linux Device Drivers [M]. 3rd Ed. O'Reilly Media Inc,2005.
  • 2Bovet D P,Cesati M. Understanding the Linux Kernel[M]. 3rd Ed. O'Reilly Media Inc,2005.
  • 3Venvenuti C. Understanding Linux Network Intemals[M]. O'Reilly Media Inc, 2006.
  • 4小高知宏.基礎からゎTCP/IP-アナラィ作成とザバケット解析[M].ォ一ム社,2002.
  • 5Stevens W R. TCP/IP Illustrated - Volume 1: The Protocols [M]. Addison Wesley Longman Ine, 1994.
  • 6BitTorrent Official Document & eMule Introduction (eDonkey).

共引文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部