通信学报 ›› 2014, Vol. 35 ›› Issue (7): 178-192.doi: 10.3969/j.issn.1000-436x.2014.07.022

• 综述 • 上一篇    下一篇

主动网络流水印技术研究进展

郭晓军1,2,3,程光1,3,朱琛刚1,3,周爱平1,3   

  1. 1 东南大学 计算机科学与工程学院,江苏 南京 210096
    2 西藏民族学院 信息工程学院,陕西 咸阳 712082
    3 东南大学 计算机网络和信息集成教育部重点实验室,江苏 南京 210096
  • 出版日期:2014-07-25 发布日期:2017-06-24
  • 基金资助:
    江苏省科技支撑计划(工业)基金资助项目;江苏省未来网络前瞻性基金资助项目;江苏省六大人才高峰基金资助项目;国家重点基础研究发展计划(“973”计划)基金资助项目;国家自然科学基金资助项目

Progress in research on active network flow watermark

Xiao-jun GUO1,2,3,Guang CHENG1,3,Chen-gang ZHU1,3,Dinh-Tu TRUONG1,3,Ai-ping ZHOU1,3   

  1. 1 School of Computer Science and Engineering, Southeast University, Nanjing 210096, China
    2 School of Information Engineering, Tibet Nationalities Institute, Xianyang 712082, China
    3 Ministry of Education Key Laboratory of Computer Network and Information Integration, Southeast University, Nanjing 210096, China
  • Online:2014-07-25 Published:2017-06-24
  • Supported by:
    Jiangsu Provincial Science and Technology Support Program—Industrial Part;The Future Net-work Proactive Program of Jiangsu Province;The Six Talent Peak Project of Jiangsu Province;The National Basic Research Program (973 Program) of China;The National Natural Science Foundation of China

摘要:

在匿名网络环境下通信双方关系确认、僵尸网络控制者追踪、中间跳板主机发现等方面,以被动网络流量分析(passive traffic analysis)为核心的传统入侵检测与流关联技术存在空间开销大、实时性差、识别率低、灵活性欠佳、难以应对加密流量等明显缺点。而将主动网络流量分析与数字水印思想相融合的主动网络流水印(ANFW,active network flow watermark)技术能有效克服传统被动网络流量分析方法的不足,已引起了国内外学者的广泛关注。首先阐述了ANFW机制的通用模型,总结了ANFW技术的分类及所涉及的角色关系;其次,详细综述了近年来提出的多种典型的基于不同网络流特征的ANFW技术,并进行对比性总结;最后,概述了当前ANFW技术自身安全威胁及应对措施现状,展望了其未来的研究方向。

关键词: 网络安全, 主动流量分析, 网络流水印, 流特征, 匿名通信, 跳板节点, 僵尸网络

Abstract:

In face of confirming user communication relationship in anonymous network, tracing botmaster and detecting stepping stones, traditional intrusion detection and flow correlation methods which mainly rely on passive traffic analysis have shown many drawbacks obviously, such as high space costs, poor real-time, low accuracy, poor flexibility, fail in dealing with encrypted traffic and so on. However, the active network flow watermark(ANFW) which combined the idea of digital watermarking and active traffic analysis can overcome the drawbacks above effectively. ANFW has aroused extensive attention of scholars at home and abroad. Firstly, the general model of ANFW is presented, and the classifica-tion of existing proposals and roles involved in ANFW are summarized. Then, several representative ANFW approaches using distinct network flow characteristics are presented and compared in detail. Finally, threats against existing ANFW technology and their corresponding countermeasures are overviewed, also some future research directions about ANFW are discussed.

Key words: network security, active traffic analysis, network flow watermark, network flow characteristics, anonymous communication, stepping stones, botnet

No Suggested Reading articles found!