首页|基于未知应用层协议识别方法的网络安全系统设计与研究

基于未知应用层协议识别方法的网络安全系统设计与研究

扫码查看
随着网络流量的爆炸式增长,未知应用层协议的识别与网络安全管理已成为当前亟待解决的问题.因此,为了提高协议识别的准确性和效率,对未知应用层协议进行研究,同时对协议负载进行多层次的分类,并使用滑动窗口技术对同组数据进行切割,以提升数据的处理效率和准确性.在特征提取方面,采用GramMatch算法来应对协议传输端口的变动情况.结果显示,在协议传输端口被修改后,GramMatch算法的识别率仅下降了 0.14%,显示出其较高的鲁棒性.与此同时,传统nD-PI技术在同类测试中的识别率却有75.52%的大幅下降.综上可以看出,这项研究不仅展示了基于未知应用协议识别方法的网络安全系统设计的有效性,还在实际应用中展示出了卓越的识别性能.
Design and Research of Network Security System Based on Unknown Application Layer Protocol Identification Method
With the explosive growth of network traffic,identifying unknown application layer protocols and managing network security have become an urgent problem to be solved.Therefore,in order to improve the accuracy and efficiency of protocol recognition,this article studied unknown application layer protocols,classified protocol loads at multiple levels,and used slid-ing window technology to segment the same group of data to improve data processing efficiency and accuracy.In terms of fea-ture extraction,this study innovatively employed the GramMatch algorithm to address changes in protocol transmission ports.The results show that after the protocol transmission port is modified,the recognition rate of the GramMatch algorithm only decreases by 0.14%,demonstrating its higher robustness.At the same time,the recognition rate of traditional nDPI technolo-gy significantly decreases by 75.52%in similar tests.In summary,this study not only demonstrates the effectiveness of net-work security system design based on unknown application protocol recognition methods,but also demonstrates excellent rec-ognition performance in practical applications.

unknown application layerprotocol identificationnetwork security systemGramMatch algorithm

江家伟、邹洪、张佳发、曾子峰、许伟杰

展开 >

南方电网数字电网集团信息通信科技有限公司,广东,广州 510663

未知应用层 协议识别 网络安全系统 GramMatch算法

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(10)