检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]河北远东通信系统工程有限公司,河北石家庄050000
出 处:《计算机与网络》2015年第8期38-40,共3页Computer & Network
摘 要:深度数据包检测应用识别测试过程中发现某些按照知识库可被识别为应用的流量识别不全,应用流量统计结果与真实流量存在差距。如何准确统计应用的流量,是一个值得思考的问题。针对应用流量识别不全问题,研究了3种解决方案:查找应用会话中所有报文的共同字符、在规则中加入peer学习和记录识别为应用会话的IP和端口号、会话老化机制。通过对3种方法的实验对比,最优的解决方案是采用会话老化机制,辅助采用peer学习和查找会话中所有报文的共同特征。In the process of the Deep Packet Inspection (Deep Packet Inspection, DPI) test, it is found that some application can be identified according to the knowledge base, but the flow of application is not complete, and the statistic result of actual application flow is different from that of real flow. How to precisely calculate the application flow is an important problem. Aiming at this problem, this paper presents three solutions such as searching conmlon character of all messages in application session, adding peer learning in rules and recording IP and port number of application session as well as session aging mechanism. The experiment results show that the optimal solution is to adopt session aging mechanism, and use peer learning and searching conmlon features of all messages in session as assistance.
关 键 词:流量识别 网络协议 识别流量与真实流量差距 会话老化 peer学习 报文共同字符
分 类 号:TP391.41[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.13