通信学报 ›› 2016, Vol. 37 ›› Issue (11): 11-22.doi: 10.11959/j.issn.1000-436x.2016214

• 学术论文 • 上一篇    下一篇

基于匿名化流表的网络数据分组实时匿名方法

韩春静1,2,3,葛敬国3,谢高岗1,李亮雄3,李佟3,刘韵洁1   

  1. 1 中国科学院计算技术研究所,北京 100190
    2 中国科学院大学,北京100049
    3 中国科学院信息工程研究所,北京 100093
  • 出版日期:2016-11-25 发布日期:2016-11-30
  • 基金资助:
    中国科学院先导专项基金资助项目;国家自然科学青年基金资助项目;国家重点基础研究发展计划(“973”计划)基金资助项目;国家高技术研究发展计划(“863”计划)基金资助项目

Online trace anonymization based on anonymous flow table

Chun-jing HAN1,2,3,Jing-guo GE3,Gao-gang XIE1,Liang-xiong LI3,Tong LI3,Yun-jie LIU1   

  1. 1 Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100190, China
    2 University of Chinese Academy of Sciences, Beijing 100049, China
    3 Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
  • Online:2016-11-25 Published:2016-11-30
  • Supported by:
    The Strategic Priority Research Program of the Chinese Academy of Sciences;The National Natural Science Youth Foundation of China;The National Basic Research Program of China (973 Program);The National High Technology Research and Development Program of China (863 Program)

摘要:

提出了基于匿名化流表的网络数据分组实时匿名方法(Fad-Pan,online trace anonymization based on the anonymous flow table),主要研究Fad-Pan算法以及研发基于DPDK的Fad-Pan原型系统。实验结果表明,Fad-Pan算法比已有的方法在匿名化速度上提高了20倍以上,单个普通服务器可以实时处理万兆链路的IPv4和IPv6流量数据。

关键词: 网络流量匿名化, Fad-Pan, AFT, DPDK

Abstract:

A real-time network packet anonymous method named Fad-Pan (online trace anonymization based on the anonymous flow table) was proposed. The Fad-Pan algorithm was studied and an online trace anonymization prototype system based on DPDK library was developed. The experimental results prove that the Fad-Pan algorithm is faster more than 20 times than the existing method, and a single server can handle the real-time IPv4 and IPv6 traffic of the 10 Gbit/s link used by the Fad-Pan.

Key words: network trace anonymization, Fad-Pan, AFT, DPDK

No Suggested Reading articles found!