计算机应用 ›› 2017, Vol. 37 ›› Issue (4): 954-959.DOI: 10.11772/j.issn.1001-9081.2017.04.0954

• 网络与通信 • 上一篇    下一篇

基于离散序列报文的协议格式特征自动提取算法

李阳, 李青, 张霞   

  1. 信息工程大学 信息系统工程学院, 郑州 450002
  • 收稿日期:2016-09-28 修回日期:2016-10-09 出版日期:2017-04-10 发布日期:2017-04-19
  • 通讯作者: 李青
  • 作者简介:李阳(1991-),男,河南柘城人,硕士研究生,主要研究方向:数据挖掘、流量分类;李青(1976-),女,河北正定人,副教授,博士,主要研究方向:网络数据逆向处理、可见光通信、无线自组织网、传感网;张霞(1979-),女,山东济南人,讲师,博士,主要研究方向:机器学习、网络协议分析。

Automatic protocol format signature construction algorithm based on discrete series protocol message

LI Yang, LI Qing, ZHANG Xia   

  1. College of Information System Engineering, Information Engineering University, Zhengzhou Henan 45002, China
  • Received:2016-09-28 Revised:2016-10-09 Online:2017-04-10 Published:2017-04-19

摘要: 针对缺少会话信息的离散序列报文,提出一种基于离散序列报文的协议格式(SPMbFSC)特征自动提取算法。SPMbFSC在对离散序列报文进行聚类的基础上,通过改进的频繁模式挖掘算法提取出协议关键字,进一步对协议关键字进行选择,筛选出协议格式特征。仿真结果表明,SPMbFSC在以单个报文为颗粒度的识别中对FTP、HTTP等六种协议的识别率均能达到95%以上,在以会话为颗粒度的识别中识别率可达90%。同等实验条件下性能优于自适应特征(AdapSig)提取方法。实验结果表明SPMbFSC不依赖会话数据的完整性,更符合实际应用中由于接收条件限制导致会话信息不完整的情形。

关键词: 离散序列报文, 协议关键字提取, 自适应特征挖掘, 格式特征, 协议识别

Abstract: To deal with the discrete series protocol message without session information, a new Separate Protocol Message based Format Signature Construction (SPMbFSC) algorithm was proposed. First, separate protocol message was clustered, then the keywords of the protocol were extracted by improved frequent pattern mining algorithm. At last, the format signature was acquired by filtering and choosing the keywords. Simulation results show that SPMbFSC is quite accurate and reliable, the recognition rate of SPMbFSC for six protocols (DNS, FTP, HTTP, IMAP, POP3 and IMAP) achieves above 95% when using single message as identification unit, and the recognition rate achieves above 90% when using session as identification unit. SPMbFSC has better performance than Adaptive Application Signature (AdapSig) extraction algorithm under the same experimental conditions. Experimental results indicate that the proposed SPMbFSC does not depend on the integrity of session data, and it is more suitable for processing incomplete discrete seriesprotocol message due to the reception limitation.

Key words: discrete series protocol message, protocol keyword extraction, dadptive format signature mining, format signature, protocol identification

中图分类号: