Journal of Computer Applications ›› 2015, Vol. 35 ›› Issue (3): 704-711.DOI: 10.11772/j.issn.1001-9081.2015.03.704

Previous Articles     Next Articles

Semi-fragile net-flow fingerprint coding scheme based on adaptive net-flow characteristic

LEI Cheng1,2, ZHANG Hongqi1,2, SUN Yi1, DU Xuehui1   

  1. 1. Information Engineering University, Zhengzhou Henan 450001, China;
    2. Henan Provincial Key Laboratory of Information Security (Information Engineering University), Zhengzhou Henan 450001, China
  • Received:2014-10-14 Revised:2014-11-21 Online:2015-03-13 Published:2015-03-10


雷程1,2, 张红旗1,2, 孙奕1, 杜学绘1   

  1. 1. 信息工程大学, 郑州 450001;
    2. 河南省信息安全重点实验室(信息工程大学), 郑州 450001
  • 通讯作者: 雷程
  • 作者简介:雷程(1989-),男,北京人,硕士研究生,主要研究方向:网络信息安全、数据安全交换;张红旗(1962-),男,河北遵化人,教授,博士生导师,博士,主要研究方向:网络安全、等级保护;孙奕(1979-),女,河南郑州人,讲师,博士研究生,主要研究方向:信息安全、数据安全交换
  • 基金资助:



Aiming at unavailability and unreliability of net-flow fingerprint caused by net-flow transformation and network jitter, a semi-fragile net-flow fingerprint coding scheme based on adaptive net-flow characteristic (ACSF) was proposed. Firstly, ACSF generated Hash Message Authentication Code (HMAC) encryption key, determined HMAC scrambling method and chose the initial phase of the Pseudo-Noise (PN) code in accordance with net-flow characteristic parameters.The space of secret key was enlarged to O((k+1)·(S·O(KEN))), so as to increase computational complexity of compromising. Besides, net-flow fingerprint was made to have the capability of self-adaption. It decreased the computational complexity of decoder to O(k2·l·nf), which enhanced the efficiency of decoding. Secondly, in order to be semi-fragile net-flow fingerprint, Direct Sequence Spread Spectrum (DSSS) was used to filter non-malicious disposing. It can reach more than 90% correctness under the condition of 66.7% multi-flow disturbance rate. Besides, HMAC was used to locate malicious tamper, which could correctly locate malicious tamper at least 98.3%. Finally, the security, accuracy of tamper localization and resisting disturbance capability of ACSF were analyzed and verified by experiments.

Key words: net-flow exchange, net-flow characteristic, self-adaption, temper localization, resisting disturbance capability, semi-fragile net-flow fingerprint



关键词: 流交换, 流特征, 自适应, 篡改定位, 抗干扰能力, 半脆弱流指纹

CLC Number: