通信学报 ›› 2015, Vol. 36 ›› Issue (3): 161-169.doi: 10.11959/j.issn.1000-436x.2015070

• 学术论文 • 上一篇    下一篇

基于流感知的复杂网络应用识别模型

张洛什1,王大伟2,薛一波3,4   

  1. 1 哈尔滨理工大学 计算机科学与技术学院,黑龙江 哈尔滨 150080
    2 国家计算机网络应急技术处理协调中心,北京 100029
    3 清华大学 信息技术研究院,北京 100084
    4 清华大学 信息科学与技术国家实验室,北京 100084
  • 出版日期:2015-03-25 发布日期:2017-06-21
  • 基金资助:
    国家科技支撑计划基金资助项目

Flow-awared identification model of sophisticated network application

Luo-shi ZHANG1,Da-wei WANG2,Yi-bo XUE3,4   

  1. 1 School of Computer Science and Technology, Harbin University of Science and Technology, Harbin 150080, China
    2 National Computer Network Emergency Response Technical Team/Coordination Center of China, Beijing 100029, China
    3 Research Institute of Information and Technology, Tsinghua University, Beijing 100084, China
    4 National Lab for Information Science and Technology, Tsinghua University Beijing 100084, China
  • Online:2015-03-25 Published:2017-06-21

摘要:

传统协议识别技术多以单网络流为识别手段,不能应对复杂网络应用多服务、多协议等特性,因此在面对复杂网络应用识别时严重失效。针对复杂网络应用的识别难题,提出了一种流感知模型,从空间、时间和流量3个维度来刻画复杂网络应用的通信特性,深度分析并挖掘了复杂网络应用的行为和状态特征;基于此模型,提出了一套快速识别复杂网络应用的方法和架构。实验结果表明,流感知模型能有效识别复杂网络应用,具有良好的识别效果。

关键词: 协议识别, 行为分析, 流感知, 复杂网络应用

Abstract:

Traditional methods of protocol identification, which is mainly based on individual flow, lose their effective-ness as dealing with sophisticated network applications. A novel model of identifying sophisticated network applications, called flow-aware model, is addressed. This proposed model abstracts the characteristics of sophisticated network appli-cations from spatial dimension, time dimension and flow dimension, and provides the detailed analysis and deeply mining in characteristics of behaviors and states. Based on this model, a framework and method of sophisticated network appli-cations identification is proposed. The experimental results demonstrate that the proposed method can achieve the pur-pose of identifying sophisticated network applications effectively.

Key words: protocol identification, behavior analysis, flow aware, sophisticated network application

No Suggested Reading articles found!