期刊文献+

面向密码协议在线安全性的监测方法 被引量:2

Monitoring approach for online security of cryptographic protocol
下载PDF
导出
摘要 为解决现有方法无法在线监测协议逻辑进行的低交互型攻击的问题,提出一种密码协议在线监测方法CPOMA。首先构建面向密码协议的特征项本体框架,以统一描述不同类型的特征项,并基于该框架首次利用模糊子空间聚类方法进行特征加权,建立个体化的密码协议特征库;在此基础上给出自学习的密码协议识别与会话实例重构方法,进而在线监测协议异常会话。实验结果表明,CPOMA不仅能够较好地识别已知协议、学习未知协议、重构会话,而且能够有效在线监测协议异常会话,提高密码协议在线运行的安全性。 Previous methods can not detect the low-interaction attacks of protocol logic. A cryptographic protocol online monitoring approach named CPOMA was presented. An ontology framework of cryptographic protocol features was constructed for the unified description of cryptographic protocol features with different types. Based on the framework, a feature weighting method was proposed by fuzzy subspace clustering first, and the individualized feature database of cryptographic protocols was built. On this basis, a self-learning method was presented for protocol identification and session rebuilding, and then abnormal protocol sessions were detected online. Experimental results show that CPOMA can identify protocols, rebuild sessions, detect abnormal sessions efficiently, and can improve the online security of cryptographic protocols.
出处 《通信学报》 EI CSCD 北大核心 2016年第6期75-85,共11页 Journal on Communications
基金 国家自然科学基金资助项目(No.61309018)~~
关键词 密码协议识别 会话重构 在线安全性 本体 子空间聚类 cryptographic protocol identification session rebuilding online security ontology subspace clustering
  • 相关文献

参考文献3

二级参考文献55

  • 1赵咏,姚秋林,张志斌,郭莉,方滨兴.TPCAD:一种文本类多协议特征自动发现方法[J].通信学报,2009,30(S1):28-35. 被引量:10
  • 2IANA, IANA port number list [EB/OL], http://www.iana.org/assignments/ portnumbers.
  • 3MOORE A, ZUEV D. Internet traffic classification using bayesian analysis techniques[A]. Proceeding of ACM SIGMETRICS[C]. Banff, Canada, 2005.50-60.
  • 4ERMAN J, ARLITT M, MAHANTI A. Traffic classification using clustering algorithms[A]. Proceedings of IEEE SIGCOMM[C]. Pisa, Italy, 2006. 281-286.
  • 5ZUEV D, MOORE A W. Traffic classification using a statistical approach[A]. Proceedings of Passive and Active Measurement Workshop[C]. Boston, USA, 2005.321-324.
  • 6BALDI M, RISSO E Using XML for efficient and modular packet processing[A]. Proceedings of IEEE Globecom[C]. USA, 2005. 447-452.
  • 7RISSO E Mario baldi: NetPDL: an extensible XML-based language for packet header description[J]. Computer Networks, 2006, 50(5): 688-706.
  • 8SEN S, SPATSCHECH O, WANG D. Accurate, scalable in-network identifcation of P2P traffic using application signatures[A]. Proceedings of WWW[C]. New York ,USA,2005.17-22.
  • 9MOORE A, PAPAGIANNAKI L. Toward the accurate identification of network applications[A]. Passive and Active Measurement Workshop[C]. Boston, MA, USA, 2005.41-54.
  • 10KARAGIANNIS T, PAPAGIANNAKI K, FALOUTSOS M. BLINC: multilevel traffic classification in the dark[A]. Proceedings of IEEE SIGCOMM'05[C]. Philadelphia, USA, 2005.21-26.

共引文献14

同被引文献3

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部