首页|未知单协议数据帧的地址分析与研究

未知单协议数据帧的地址分析与研究

扫码查看
网络协议是网络通信中一系列标准的集合,未知协议的识别和分析对网络监管、保障网络安全具有重大意义.协议识别技术多种多样,但在协议的分析识别过程中,为了实现协议的简单高效识别,通常需要将未知混合多协议分离为单协议,然后再进行进一步的识别.在将未知混合数据帧分离为单协议的基础上,提出了一种高效的确定单协议位置信息的方法,即进一步将单协议的数据帧按地址分为点对点数据帧,从而实现未知协议的最终识别.最后通过分析ARP、TCP数据对该方法进行评估,结果表明采用该方法可以找到2/3以上的地址信息.
Analysis and Research on Address Message of Unknown Single Protocol Data Frame
Network protocols are sets of standards for certain network communications.The protocol identification and analysis have great significance for network management and security.The technologies of protocol identification are varied,but in the process of protocol identification, in order to simplify the identification process and improve the efficiency of protocol identification,it usually needs to separate the unknown mixed multi-protocol into single protocol, and then makes further identification.This paper presented an efficient method to determine the single protocol address message based on the previous work to separate unknown mixed data frame into single protocol.By this way the data frames of single protocol are split into point to point data frame according to the address, and then the final identification of unknown protocol is achieved.In the end,we evaluated the method by analyzing the ARP and TCP data.The results show that this method can find out more than 2/3 address information.

Protocol identificationSeparate protocolSingle protocolData frameAddress message

郑杰、朱强

展开 >

电子科技大学计算机科学与工程学院 成都611731

重庆电子工程职业学院 重庆401331

协议识别 协议分离 单协议 数据帧 地址信息

中国工程物理研究院科技发展基金NSAF联合基金国家信息安全发展计划

2012A0403021U12301062013F098

2015

计算机科学
重庆西南信息有限公司(原科技部西南信息中心)

计算机科学

CSTPCDCSCD北大核心
影响因子:0.944
ISSN:1002-137X
年,卷(期):2015.42(11)
  • 3
  • 6