首页 | 本学科首页   官方微博 | 高级检索  
     

基于流记录的主干网活跃IP地址空间检测
引用本文:张凌峰,丁伟,龚俭,缪丽华.基于流记录的主干网活跃IP地址空间检测[J].软件学报,2016,27(S2):43-49.
作者姓名:张凌峰  丁伟  龚俭  缪丽华
作者单位:东南大学 计算机科学与工程学院, 江苏 南京 211189,东南大学 计算机科学与工程学院, 江苏 南京 211189,东南大学 计算机科学与工程学院, 江苏 南京 211189,东南大学 计算机科学与工程学院, 江苏 南京 211189
基金项目:国家高技术研究发展计划(863)(2015AA015603);江苏省未来网络创新研究院研究项目(BY2013095-5-03)
摘    要:掌握IP地址的实际使用情况对于网络管理和网络安全等研究领域有着重要的意义.提出一种以抽样流记录为分析数据源的活跃地址检测算法,其核心思路是将存在双向通信流量作为地址活跃判定条件.算法基于被动测量技术,以流记录为分析数据源使其可以在主干网边界运行.讨论了抽样、伪造地址等问题对算法的影响以及相应的应对策略,用DPI分析检验了算法的准确性和有效性.最后基于NBOS平台,将其部署在CERNET全部38个主节点,完成了全网活跃IP地址空间的检测.

关 键 词:IP地址活跃性  流记录  抽样  双向通信流量
收稿时间:2015/5/31 0:00:00
修稿时间:1/5/2016 12:00:00 AM

Backbone Active IP Address Space Detection Based on Flow Records
ZHANG Ling-Feng,DING Wei,GONG Jian and MIAO Li-Hua.Backbone Active IP Address Space Detection Based on Flow Records[J].Journal of Software,2016,27(S2):43-49.
Authors:ZHANG Ling-Feng  DING Wei  GONG Jian and MIAO Li-Hua
Affiliation:School of Computer Science and Engineering, Southeast University, Nanjing 211189, China,School of Computer Science and Engineering, Southeast University, Nanjing 211189, China,School of Computer Science and Engineering, Southeast University, Nanjing 211189, China and School of Computer Science and Engineering, Southeast University, Nanjing 211189, China
Abstract:Understanding the utilization of IP addresses is very important for the research of network administrators and network security. This paper proposes a methodology of detecting active IP addresses based on sampled flow records. The core idea of the methodology is that IP addresses with two-way communication traffic are active. The method is based on passive measurements and uses sampled flow records as data source, making it possible to be deployed at the boundary of backbones. Furthermore, the impacts of flows'' sampling and spoofed traffic on the method are discussed. DPI technology is used to validate accuracy and efficiency of the method. Finally, the method is deployed at all 38 nodes of CERNET, detecting active IP address space in the whole CERENT network.
Keywords:IP address activity  flow records  sampling  two-way traffic
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号