网络协议流量识别方法研究  被引量:4

A Survey of Network Protocol Traffic Identification

在线阅读下载全文

作  者:孟博[1] 何旭东[1] 王德军[1] 刘加兵 MENG Bo;HE Xudong;WANG Dejun;LIU Jiabing(College of Computer Science,South-central University for Nationalities,Wuhan 430074,China)

机构地区:[1]中南民族大学计算机科学学院

出  处:《郑州大学学报(理学版)》2019年第4期68-74,共7页Journal of Zhengzhou University:Natural Science Edition

基  金:湖北省自然科学基金项目(2014CFB249,2018ADC150);中南民族大学中央高校基本科研业务费专项资金项目(CZZ19003,QSZ17007)

摘  要:网络协议流量识别旨在识别流量所属的网络应用或者协议,进而及时发现和处理网络故障和安全漏洞,提高网络服务质量和保障网络空间安全.首先总结4种主要网络协议流量识别方法:基于行为的识别方法、基于负载随机性的识别方法、基于有效负载的识别方法和基于统计学特征的识别方法;然后分别基于在线加密流量、在线非加密流量、离线加密流量和离线非加密流量4种应用场景,对相关研究成果进行归类总结和讨论;最后总结全文并展望未来网络协议流量识别方法的研究方向.Network protocol traffic identification aimed to find and deal with network faults and security vulnerabilities by identifying the flow generated by network applications and protocols.The quality of network service was improved and the security of network space was guaranted.Firstly,four types of network protocol traffic identification methods were summarized,i.e.,behavior-based identification,payload-based identification,entropy-based identification,and statistical feature-based identification.And then based on the four application scenarios,i.e.,online encrypted traffic,online unencrypted traffic,offline encrypted traffic and offline unencrypted traffic,the related research results were categorized and discussed.Finally,the conclusions were drawn,and the several future research directions of network protocol traffic identification were pointed out.

关 键 词:在线流量 离线流量 加密流量 非加密流量 网络管理 网络安全 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象