首页 | 本学科首页   官方微博 | 高级检索  
     

基于离散序列报文的协议格式特征自动提取算法
引用本文:李阳,李青,张霞. 基于离散序列报文的协议格式特征自动提取算法[J]. 计算机应用, 2017, 37(4): 954-959. DOI: 10.11772/j.issn.1001-9081.2017.04.0954
作者姓名:李阳  李青  张霞
作者单位:信息工程大学 信息系统工程学院, 郑州 450002
摘    要:针对缺少会话信息的离散序列报文,提出一种基于离散序列报文的协议格式(SPMbFSC)特征自动提取算法。SPMbFSC在对离散序列报文进行聚类的基础上,通过改进的频繁模式挖掘算法提取出协议关键字,进一步对协议关键字进行选择,筛选出协议格式特征。仿真结果表明,SPMbFSC在以单个报文为颗粒度的识别中对FTP、HTTP等六种协议的识别率均能达到95%以上,在以会话为颗粒度的识别中识别率可达90%。同等实验条件下性能优于自适应特征(AdapSig)提取方法。实验结果表明SPMbFSC不依赖会话数据的完整性,更符合实际应用中由于接收条件限制导致会话信息不完整的情形。

关 键 词:离散序列报文  协议关键字提取  自适应特征挖掘  格式特征  协议识别  
收稿时间:2016-09-28
修稿时间:2016-10-09

Automatic protocol format signature construction algorithm based on discrete series protocol message
LI Yang,LI Qing,ZHANG Xia. Automatic protocol format signature construction algorithm based on discrete series protocol message[J]. Journal of Computer Applications, 2017, 37(4): 954-959. DOI: 10.11772/j.issn.1001-9081.2017.04.0954
Authors:LI Yang  LI Qing  ZHANG Xia
Affiliation:College of Information System Engineering, Information Engineering University, Zhengzhou Henan 45002, China
Abstract:To deal with the discrete series protocol message without session information, a new Separate Protocol Message based Format Signature Construction (SPMbFSC) algorithm was proposed. First, separate protocol message was clustered, then the keywords of the protocol were extracted by improved frequent pattern mining algorithm. At last, the format signature was acquired by filtering and choosing the keywords. Simulation results show that SPMbFSC is quite accurate and reliable, the recognition rate of SPMbFSC for six protocols (DNS, FTP, HTTP, IMAP, POP3 and IMAP) achieves above 95% when using single message as identification unit, and the recognition rate achieves above 90% when using session as identification unit. SPMbFSC has better performance than Adaptive Application Signature (AdapSig) extraction algorithm under the same experimental conditions. Experimental results indicate that the proposed SPMbFSC does not depend on the integrity of session data, and it is more suitable for processing incomplete discrete seriesprotocol message due to the reception limitation.
Keywords:discrete series protocol message  protocol keyword extraction  dadptive format signature mining  format signature  protocol identification  
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号