With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network str...With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network.展开更多
介绍了一种面向TCP连接的网络实时监控系统RMCNS(a real-time monitoring and controlling network system to orient TCP connection)。该系统的架构搭建在网络入侵监测系统函数库(Libnids)编程平台上,采用网络侦听方式监控攻击、实...介绍了一种面向TCP连接的网络实时监控系统RMCNS(a real-time monitoring and controlling network system to orient TCP connection)。该系统的架构搭建在网络入侵监测系统函数库(Libnids)编程平台上,采用网络侦听方式监控攻击、实时高效的TCP协议还原、基于内容的攻击判定和面向TCP连接的实时阻断是RMCNS的主要特点,该文重点讨论了针对基于TCP连接的攻击实时响应的阻断技术,分别介绍了在标准TCP协议栈和非标准TCP协议栈网络环境下,RMCNS采用的阻断技术,为网络监控提出了新的方法。展开更多
对TCP实时视频传输过程进行分析,指出发送延时是影响基于TCP的实时视频传输端到端延时的关键因素,并可通过其大小来判断视频帧的播放质量;提出一种递阶式马尔可夫预测模型,该模型通过输入视频帧长度、丢包率、网络往返时间和TCP拥塞窗...对TCP实时视频传输过程进行分析,指出发送延时是影响基于TCP的实时视频传输端到端延时的关键因素,并可通过其大小来判断视频帧的播放质量;提出一种递阶式马尔可夫预测模型,该模型通过输入视频帧长度、丢包率、网络往返时间和TCP拥塞窗口大小预测视频帧的发送延时,使用NS2(Network simulator 2)进行模拟。研究结果表明:在RED(Random early detection)策略下,可以通过模型的预测值来判断视频帧是否适合采用TCP传输,能为基于TCP的流媒体传输策略提供重要参考。展开更多
基金National High-Tech Research and Development Program of China (863 Program) (No.2007AA01Z309)
文摘With the continual growth of the variety and complexity of network crime means, the traditional packet feature matching cannot detect all kinds of intrusion behaviors completely. It is urgent to reassemble network stream to perform packet processing at a semantic level above the network layer. This paper presents an efficient TCP stream reassembly mechanism for real-time processing of high-speed network traffic. By analyzing the characteristics of network stream in high-speed network and TCP connection establishment process, several polices for designing the reassembly mechanism are built. Then, the reassembly implementation is elaborated in accordance with the policies. Finally, the reassembly mechanism is compared with the traditional reassembly mechanism by the network traffic captured in a typical gigabit gateway. Experiment results illustrate that the reassembly mechanism is efficient and can satisfy the real-time property requirement of traffic analysis system in high-speed network.
文摘介绍了一种面向TCP连接的网络实时监控系统RMCNS(a real-time monitoring and controlling network system to orient TCP connection)。该系统的架构搭建在网络入侵监测系统函数库(Libnids)编程平台上,采用网络侦听方式监控攻击、实时高效的TCP协议还原、基于内容的攻击判定和面向TCP连接的实时阻断是RMCNS的主要特点,该文重点讨论了针对基于TCP连接的攻击实时响应的阻断技术,分别介绍了在标准TCP协议栈和非标准TCP协议栈网络环境下,RMCNS采用的阻断技术,为网络监控提出了新的方法。
文摘对TCP实时视频传输过程进行分析,指出发送延时是影响基于TCP的实时视频传输端到端延时的关键因素,并可通过其大小来判断视频帧的播放质量;提出一种递阶式马尔可夫预测模型,该模型通过输入视频帧长度、丢包率、网络往返时间和TCP拥塞窗口大小预测视频帧的发送延时,使用NS2(Network simulator 2)进行模拟。研究结果表明:在RED(Random early detection)策略下,可以通过模型的预测值来判断视频帧是否适合采用TCP传输,能为基于TCP的流媒体传输策略提供重要参考。