高效可扩展的应用层流量识别架构  被引量:1

Efficient and extensible architecture of traffic identification at application layer

在线阅读下载全文

作  者:张众[1,2] 杨建华[1] 谢高岗[1] 

机构地区:[1]中国科学院计算技术研究所,北京100190 [2]中国科学院研究生院,北京100039

出  处:《通信学报》2008年第12期22-31,共10页Journal on Communications

基  金:国家重点基础研究发展计划(“973”计划)基金资助项目(2007CB310702);国家自然科学基金资助项目(90604015);中国科学院重大科研装备研制基金资助项目(YZ200824)~~

摘  要:提出一种采用自定义识别方法描述语言和识别操作树的高效可扩展的应用层流量识别架构(ARTIST)。在流量识别方法的描述模型分析的基础上,设计了识别方法和识别规则描述语言以及对应的识别引擎,实现各种主要流量识别方法,并可动态扩展新的识别方法。采用识别规则树结构维护识别规则,缩短了协议识别流程,提高了识别性能。实验证明ARTIST不仅能够支持对各类的流量识别方法和规则的动态更新,而且能够提高系统识别性能。The application identification system is required to be extensible and efficient for abundant rules and their frenquent updating. A new architecture of traffic identification ARTIST (architecture of traffic identification with script and operation tree) was proposed. An identification description language and its engine have been designed to support deep packet inspection, traffic statistics signature matching, multi-state combination based on a describing model for application identification method which can cover all existing identification methods in ARTIST. New identification method can be updated online with the script expediently. An identification operation tree structure is used to lessen the average identification rules quantity for packet checking. The experiment result shows that the ARTIST can both support the dynamic update for identification methods and rules and acquire a higher performance for high bandwidth.

关 键 词:流量识别 描述语言 识别方法树 规则更新 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象