With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network str...With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network.展开更多
针对TCP(Transm ission Control Protocol)协议在高速卫星因特网中传输吞吐量低的问题,提出了一种改进TCP快速恢复的算法。该算法根据卫星信道由传输错误造成的分组丢失概率远大于由拥塞造成的分组丢失概率的特点,通过加快窗口的增长速...针对TCP(Transm ission Control Protocol)协议在高速卫星因特网中传输吞吐量低的问题,提出了一种改进TCP快速恢复的算法。该算法根据卫星信道由传输错误造成的分组丢失概率远大于由拥塞造成的分组丢失概率的特点,通过加快窗口的增长速度,避免过早地进入拥塞避免阶段,达到了提高TCP吞吐量的目的。通过NS2软件模拟仿真了高速卫星因特网环境,并对各个TCP版本和改进算法的仿真结果进行了比较和分析。仿真结果表明,改进算法的吞吐量比TCP-SACK提高了约10%,比TCP-Reno提高了约30%。展开更多
基金National High-Tech Research and Development Program of China (863 Program) (No.2007AA01Z309)
文摘With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network.
文摘针对TCP(Transm ission Control Protocol)协议在高速卫星因特网中传输吞吐量低的问题,提出了一种改进TCP快速恢复的算法。该算法根据卫星信道由传输错误造成的分组丢失概率远大于由拥塞造成的分组丢失概率的特点,通过加快窗口的增长速度,避免过早地进入拥塞避免阶段,达到了提高TCP吞吐量的目的。通过NS2软件模拟仿真了高速卫星因特网环境,并对各个TCP版本和改进算法的仿真结果进行了比较和分析。仿真结果表明,改进算法的吞吐量比TCP-SACK提高了约10%,比TCP-Reno提高了约30%。