通信学报 ›› 2016, Vol. 37 ›› Issue (6): 75-85.doi: 10.11959/j.issn.1000-436x.2016293

• 学术论文 • 上一篇    下一篇

面向密码协议在线安全性的监测方法

朱玉娜1,2,韩继红1,袁霖1,范钰丹1,陈韩托1,谷文1   

  1. 1 解放军信息工程大学三院,河南 郑州 450001
    2 解放军91033部队,山东 青岛 266035
  • 出版日期:2016-06-25 发布日期:2016-07-28
  • 基金资助:
    国家自然科学基金资助项目

Monitoring approach for online security of cryptographic protocol

Yu-na ZHU1,2,Ji-hong HAN1,Lin YUAN1,Yu-dan FAN1,Han-tuo CHEN1,Wen GU1   

  1. 1 The Third College,PLA Information Engineering University,Zhengzhou 450001,China
    2 Troops 91033 of PLA,Qingdao 266035,China
  • Online:2016-06-25 Published:2016-07-28
  • Supported by:
    The National Natural Science Foundation of China

摘要:

为解决现有方法无法在线监测协议逻辑进行的低交互型攻击的问题,提出一种密码协议在线监测方法CPOMA。首先构建面向密码协议的特征项本体框架,以统一描述不同类型的特征项,并基于该框架首次利用模糊子空间聚类方法进行特征加权,建立个体化的密码协议特征库;在此基础上给出自学习的密码协议识别与会话实例重构方法,进而在线监测协议异常会话。实验结果表明,CPOMA不仅能够较好地识别已知协议、学习未知协议、重构会话,而且能够有效在线监测协议异常会话,提高密码协议在线运行的安全性。

关键词: 密码协议识别, 会话重构, 在线安全性, 本体, 子空间聚类

Abstract:

Previous methods can not detect the low-interaction attacks of protocol logic.A cryptographic protocol online monitoring approach named CPOMA was presented.An ontology framework of cryptographic protocol features was constructed for the unified description of cryptographic protocol features with different types.Based on the framework,a feature weighting method was proposed by fuzzy subspace clustering first,and the individualized feature database of cryptographic protocols was built.On this basis,a self-learning method was presented for protocol identification and session rebuilding,and then abnormal protocol sessions were detected online.Experimental results show that CPOMA can identify protocols,rebuild sessions,detect abnormal sessions efficiently,and can improve the online security of cryptographic protocols.

Key words: cryptographic protocol identification, session rebuilding, online security, ontology, subspace clustering

No Suggested Reading articles found!