北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2008, Vol. 31 ›› Issue (2): 95-98.doi: 10.13190/jbupt.200802.95.wangj

• 研究报告 • 上一篇    下一篇

基于可信列表的启发式流量检测模型

王 蛟, 周亚建, 杨义先   

  1. 北京邮电大学 网络与交换技术国家重点实验室信息安全中心,北京 100876
  • 收稿日期:2007-07-11 修回日期:1900-01-01 出版日期:2008-04-28 发布日期:2008-04-28
  • 通讯作者: 王 蛟

A Heuristic Traffic Identification Method Based on Trusted List

WANG Jiao, ZHOU Ya-jian, YANG Yi-xian   

  1. Information Security Center, State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Received:2007-07-11 Revised:1900-01-01 Online:2008-04-28 Published:2008-04-28
  • Contact: WANG Jiao

摘要:

在分析了现有流量检测技术不足的基础上提出了一种基于可信列表的启发式流量检测方法。该方法采用了“记忆”技术,通过将已识别的连接加入到一个可信列表中,并实时优化该列表,使得比较活跃的网络连接始终能够在列表中优先被检测到,从而加快流量检测速度,提高准确度。实验证明,该方法对加密流量的检测效果非常理想,相比于现有检测方法更具效率,识别率可达到95%以上。

关键词: 对等网络, 流量检测, 可信列表, 深度包检测

Abstract:

The insufficient of current traffic identification technique was analyzed, and then a heuristic traffic identification method based on trusted list was proposed. This method uses a “memory” technique, adds the discerned connection into a trusted list. Moreover, a real-time optimized method was developed to make sure that the more active connections can be measured to primarily in the trusted list all the time, thus will accelerate the traffic identification speed and improve the accuracy. The experiment results show that this method can identify the encrypted traffic perfectly, and more effectively than existed methods.

Key words: peer-to-peer, traffic identification, trusted list, deep packet inspection

中图分类号: