期刊文献+

一种面向网络安全分析的高速流重组优化方案 被引量:5

A High-speed Network Flow Reassembly Optimized Scheme for Network Security Analysis
下载PDF
导出
摘要 在高速网络环境下,网络流量采集和重组是进行网络安全分析的重要前提。文章针对网络安全分析的准确性和实时性要求,提出了一种面向网络安全分析的高速流重组优化方案。首先,在基于Hash结构的流表方案中,设计了多流表并行化机制,并通过在高速网络流的分发策略中引入反馈信息,解决了高速网络流在多个流表间分发的负载均衡问题;其次,为进一步降低流老化检测开销,在流表方案中特别设计了活跃队列,将流记录按最近最少使用顺序排列,避免全流表遍历操作,降低了流老化检测的时间复杂度;最后,文章利用DPDK实现了基于流表优化方案的高速网络流重组系统,并对该流表优化方案的准确性和实时性进行了验证。实验结果表明,在网络带宽为10 Gbps时,丢包率为0.002%,能有效满足高速网络环境下网络安全分析的数据需求。 In high-speed network environment, network traffic collection and reassembly is an important prerequisite for network security analysis. To meet the need of the accuracy and realtime requirement of network security analysis, a high-speed network flow reassembly optimization scheme is proposed in this paper. Firstly, a parallel mechanism of multi-flow tables is designed in the Hash-based flow table scheme, the load balancing problem of high-speed network flows distributed among multiple flow tables is solved by introducing feedback information into the distribution strategy of high-speed network flows. Secondly, in order to further reduce the overhead of flow aging detection, an active queue is designed in the flow table scheme. Records are arranged in the order of least recent usage, which could avoid full flow table traversal operation and reduce the time complexity of flow aging detection. Finally, a high-speed network flow reassembly system based on flow table optimization scheme is implemented by DPDK, and the accuracy and real-time performance of the flow table optimization scheme are verified. The experimental results show that when the network bandwidth is 10 Gbps, the packet loss rate is 0.002%, which can effectively meet the data requirements of network security analysis in high-speed network environment.
作者 陈良国 阮树骅 陈兴蜀 罗永刚 CHEN Liangguo;RUAN Shuhua;CHEN Xingshu;LUO Yonggang(College of Cybersecurity,Sichuan University,Chengdu Sichuan 610065,China;Cybersecurity Research Institute,Sichuan University,Chengdu Sichuan 610065,China)
出处 《信息网络安全》 CSCD 北大核心 2019年第11期82-90,共9页 Netinfo Security
基金 国家自然科学基金青年科学基金[61802270] 中央高校基本科研业务费基础研究项目[SCU2018D018]
关键词 安全分析 流重组 多流表 活跃队列 负载均衡 security analysis flow reassembly multi-flow table active queue load balancing
  • 相关文献

参考文献2

二级参考文献13

  • 1闫丽丽,涂天禄,周兴涛.Libpcap数据包捕获机制剖析与研究[J].网络安全技术与应用,2006(4):38-40. 被引量:12
  • 2William S. SNMP, SNMPv2, SNMPv3 and RMON 1 and 2 [M] Reading, MA: Addison-Wesley Professional, 1999.
  • 3TCPDUMP/LIBPCAP public repository [EB/OL]. [2010-01- 09] http://www, tcpdump, org.
  • 4Claffy K C, Braun H W, et al. A parameterizable methodology for Internet traffic flow profiling [J]. IEEE Journal on Selected Areas in Communications, 1995, 13(8) 10-23.
  • 5Liu Yang, Dang T, et al. An information-theoretic approach to network monitoring and measurement [C] //Proc of the 5th ACM SIGCOMM Conf on Internet Measurement (IMC'05). Piscataway, NJ: IEEE, 2005.
  • 6Cisco. Introduction to Cisco IOS NetFlow [EB/OL]. [2010- 01-12 ]. http://www, cisco, com/en/US/prod/collateral/ iosswrel/ps6537/ps6555/ps6601/prod_ white _ paper0900aecd 80406232. pdf.
  • 7Cisco. NetFlow v5 Record Format [EB/OL]. [2010-01-12]. https://hto, bluecoat, com/packetguide/8. 5/info/netflow5- records, htm.
  • 8Cisco. NetFlow Version 9 Flow-Record Format [EB/OL]. [2010 01-12]. http://www, cisco, com/en/US/technologies[ tk648/tk362/techn--ologies white_ paper09186a00800a3db9 _ ps660 l_Product s_White_Paper, html.
  • 9Cisco. Q-Q plot [EB/OL]. [ 2010-01-14 ]. http://en. wikipedia, org/wiki/Q-Q_plot.
  • 10Liu Y, Towsley D, et al. An information theoretic approach to network trace compression [R]. New York: University of Massachusetts, 2004.

共引文献13

同被引文献24

引证文献5

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部