基于聚类法改进JA3指纹识别的恶意加密流量识别  

Improved Malicious Encrypted Traffic Identification Based on Clustering Method for JA3 Fingerprint Recognition

在线阅读下载全文

作  者:刘经纬 赵晶睛[1] 贾磊 白梦莹 于潼 方颖[1] LIU Jingwei;ZHAO Jingjing;JIA Lei;BAI Mengying;YU Tong;FANG Ying(Tianjin Institute of Navigation Instruments,Tianjin 300131,China)

机构地区:[1]天津航海仪器研究所,天津300131

出  处:《信息安全与通信保密》2022年第12期73-80,共8页Information Security and Communications Privacy

摘  要:随着互联网的发展及政务、商务领域电子化的普及,基于信息安全和隐私保护的需求,以及人们的信息安全意识日益提高。现阶段,数据的传输和通信大量采用加密技术,使加密流量呈爆发式增长。加密流量在保护个人数据安全的同时也让恶意流量的传播变得更加隐蔽,恶意加密流量检测已经成为信息安全领域的一个重要研究方向。基于此,提出一种基于JA3指纹识别技术的恶意加密流量识别方法,在传统JA3技术的基础上通过聚类法识别恶意流量,不经过解密即可对加密流量进行识别。With the development of the Internet and the popularization of e-government and business,based on the demand for information security and privacy protection,people’s awareness of information security is increasing.Nowadays,encryption is used extensively in the transmission and communication of data,which leads to an explosive growth of encrypted traffic.While encrypted traffic protects personal data security,it also makes the spread of malicious traffic more covert,and malicious encrypted traffic detection becomes an important research direction in the field of information security.In view of this,this paper proposes a malicious encrypted traffic identification method based on JA3 fingerprint identification technology,which identifies malicious traffic by clustering method on the basis of traditional JA3 technology and can identify encrypted traffic without decryption.

关 键 词:JA3 信息安全 恶意流量识别 加密流量 

分 类 号:TP393.0[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象