基于Storm的协议还原框架  被引量:1

Protocol restore framework based on Storm

在线阅读下载全文

作  者:陈兴蜀 王岳[1,2] 罗永刚 王煜骢 

机构地区:[1]四川大学网络空间安全研究院,四川成都610065 [2]四川大学计算机学院,四川成都610065

出  处:《华中科技大学学报(自然科学版)》2018年第1期1-5,21,共6页Journal of Huazhong University of Science and Technology(Natural Science Edition)

基  金:国家自然科学基金资助项目(61272447)

摘  要:针对现有的高速网络环境下,网络安全分析框架缺乏协议还原过程,导致准确性差和整体架构不易扩展的问题,提出一个基于Storm的协议还原框架.该框架使用高性能数据包捕获工具抓取数据包,并且基于其上实现分布式的实时网络流量处理模块,完整地还原了网络会话.此外通过使用内存管理和基于树状布隆过滤器的传输控制协议(TCP)还原策略提高其系统运行效率及准确率.最后通过验证得出:该系统可以实现万兆流量的捕获及采集,扩展性良好,易于在大规模集群中部署,而且准确率高.In the existing high-speed network environment,the network security analysis framework lacked the protocol restoring process.It led to the problem of poor accuracy and the overall structure was extremely diffcult to scale this series of issues.An application layer protocol restore framework on storm was presented to address the previously mentioned problems.Besides a high performance packet capture tool was used by the framework to capture data packets.And the distributed real time network traffic processing module was realized.On top of that with using the technology including memory management and the transmission control protocol(TCP) restore strategy based on tree bloom filter,the system has a improvement on its efficiency.It proved that the system can realize the capture and collection of the 10 Gbps.Apart form that the framework pocess haghly scalability and time-saving deployment in large scale clusters,and then it was accurate.

关 键 词:分布式 大数据 包抓取 传输控制协议 协议还原 

分 类 号:TP302[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象