计算机应用 ›› 2012, Vol. 32 ›› Issue (07): 1807-1811.DOI: 10.3724/SP.J.1087.2012.01807

• 网络与通信 • 上一篇    下一篇

网络汇聚点传输层拓扑的流量识别

张剑1,2,曹萍3,寿国础2   

  1. 1. 闽江学院 计算机科学系,福州350008
    2. 北京邮电大学 信息与通信工程学院,北京100876
    3. 福州大学 公共管理学院,福州350008
  • 收稿日期:2012-01-16 修回日期:2012-03-10 发布日期:2012-07-05 出版日期:2012-07-01
  • 通讯作者: 张剑
  • 作者简介:张剑(1974-),男,甘肃武威人,讲师,博士,主要研究方向:网络流量识别与分类;曹萍(1971-),女,重庆江津人,副教授,博士,主要研究方向:决策理论与技术;寿国础(1965-),男,浙江诸暨人,教授,博士生导师,主要研究方向:光接入网。
  • 基金资助:

    国家863计划项目(2008AA01Z218)

Traffic identification based on transport-layer topology at network aggregation point

ZHANG Jian1,2,CAO Ping3,SHOU Guo-chu2   

  1. 1. Department of Computer Science, Minjiang University, Fuzhou Fujian 350008, China;
    2. School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China
    3. School of Public Management, Fuzhou University, Fuzhou Fujian 350008, China
  • Received:2012-01-16 Revised:2012-03-10 Online:2012-07-05 Published:2012-07-01
  • Contact: ZHANG Jian

摘要: 针对利用数据流统计特性的网络流量分类算法复杂及实时性差的问题,提出一种基于传输层拓扑的网络流量识别方法,根据应用类型在汇聚节点表现出不同的主机连接拓扑结构,提取应用类型的拓扑特征,结合深度包检测(DPI)技术生成应用类型库,并基于该库和启发式准则实现典型应用类型的快速识别和分类。实验结果表明,所提方法对各主要应用类型的识别精确度均高于85%,并将未识别流比例从深度包检测技术的18%降低到7%,有效利用了不同应用类型的连接拓扑信息,能提高应用类型的识别准确度。

关键词: 流量识别, 传输层, 拓扑结构, 应用类型库

Abstract: Considering the complexity and poor real-time quality of classification algorithms based on the statistical characteristics of network traffic, a new traffic identification method was proposed based on transport-layer topology. According to the different host connection characteristics in terms of application types at aggregation point, the proposed method extracted topological characteristics of application types by capturing the transport layer connection information, and then produced application type pools based on Deep-in Packet Inspection (DPI) technique, finally identified the application types of traffic combining the pools and heuristic rules. The experimental results show that the proposed method gains precision higher than 85% for identifying main application types and reduces ratio of un-identified flows from 18% to 7%. It utilizes transport-layer topology information of different application types and can enhance the recognition accuracy of application types.

Key words: traffic identification, transport layer, topological structure, application type pool

中图分类号: