摘要
区块链的应用逐渐广泛,随着安全事件频发,对区块链网络的监管变得尤为重要,识别区块链流量是安全监管的第一步。作为具有代表性的区块链技术,以太坊采用私有RLPx协议对应用层内容进行了格式化和加密,导致传统的加密流量识别方法难以准确识别以太坊加密流量。在充分研究了RLPx协议后,文章设计了一种以以太坊节点活跃度为基础,结合以太坊流量高端口号、报文长度等特征的以太坊加密流量识别方法,在实验中达到了95%以上的以太坊加密TCP流量识别准确率。
With the application range of blockchain continues to expand,illegal incidents against the blockchain are becoming more frequent,the supervision of the blockchain becomes particularly important.And the recognition of blockchain traffic is the first step in blockchain supervision.As the representative of blockchain technology,ethereum uses private RLPx protocol to format and encrypt the application layer content,resulting in traditional encrypted traffic recognition method is difficult to accurately recognize ethereum encrypted traffic.After a full study of the RLPx protocol,we proposed an ethereum encrypted traffic recognition method based on ethereum active node-base,combined with features such as the high port number and the length of the packets,etc.And we have achieved more than 95%accuracy of Ethereum traffic recognition in the experiment.
作者
胡晓艳
童钟奇
吴桦
许昱玮
Hu Xiaoyan;Tong Zhongqi;Wu Hua;Xu Yuwei(School of Cyber Science and Engineering,Southeast University,Jiangsu Nanjing 211189;Key Laboratory of Computer Network and Information Integration(Southeast University),Ministry of Education,Jiangsu Nanjing 211189;Research Base of International Cyberspace Governance(Southeast University),Jiangsu Nanjing 211189;Purple Mountain Laboratories for Network and Communication Security,Jiangsu Nanjing 211111)
出处
《网络空间安全》
2020年第8期34-39,共6页
Cyberspace Security
基金
东南大学至善青年学者支持计划资助。
关键词
以太坊
RLPx加密协议
加密流量识别
区块链监管
ethereum
RLPx protocol
recognition of encrypted traffic
supervision of blockchain