首页 | 官方网站   微博 | 高级检索  
     

面向比特流的未知协议识别与分析技术综述
引用本文:雷东,王韬,马云飞. 面向比特流的未知协议识别与分析技术综述[J]. 计算机应用研究, 2016, 33(11)
作者姓名:雷东  王韬  马云飞
作者单位:军械工程学院 信息工程系,军械工程学院 信息工程系,军械工程学院 信息工程系
基金项目:国家自然科学基金资助项目(61272491);国家自然科学基金资助项目(61173191);
摘    要:在日益严峻的网络安全形势下,为确保信息的安全性,大量的网络应用开始采用未知的私有协议进行数据传输,尤其是在军事对抗中的战场无线通信网络下,通信所采用的协议不仅未知,还有可能被加密。要从截获的通信比特流中提取可用信息并加以利用,推断出以比特流形式存在的未知协议的报文格式是首要前提。首先从整体上介绍了现有面向比特流的协议识别研究领域所涉及的主要内容,重点分析了现有未知协议格式推断方法,包括频繁模式挖掘、关联规则挖掘、比特流帧切分以及协议格式推断,最后总结其优缺点及下一步研究方向。

关 键 词:未知协议   比特流  协议格式推断  协议识别
收稿时间:2016-01-28
修稿时间:2016-09-14

A Survey of Bit Stream oriented Unknown ProtocolIdentification and Analysis Techniques
Lei Dong,Wang Tao and Ma Yunfei. A Survey of Bit Stream oriented Unknown ProtocolIdentification and Analysis Techniques[J]. Application Research of Computers, 2016, 33(11)
Authors:Lei Dong  Wang Tao  Ma Yunfei
Affiliation:Dept. of Information Engineering,Ordnance Engineering College,Dept. of Information Engineering,Ordnance Engineering College,Dept. of Information Engineering,Ordnance Engineering College
Abstract:In the increasingly serious network security situation, a large number of network applications are beginning to use unknown proprietary protocols for data transmission to ensure the security of the information. Moreover, the protocols for data transmission are not only unknown but also may be encrypted under the wireless communication network of military confrontation. In order to extract information available for using from bit streams intercepted, inferring the format of unknown protocol existing in the form of bit stream is the primary prerequisite. In this paper, the existing main contents of bit stream oriented protocol identification research field are introduced completely first; then the method of inferring the format of unknown protocol including frequent pattern mining, association rule mining, frame segmentation and protocol format inferring is analyzed emphatically; finally the advantages and disadvantages are summarized and future research directions are presented.
Keywords:unknown protocol   bit stream   protocol format inferring   protocol identification
点击此处可从《计算机应用研究》浏览原始摘要信息
点击此处可从《计算机应用研究》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号