作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2021, Vol. 47 ›› Issue (11): 192-197. doi: 10.19678/j.issn.1000-3428.0059551

• 移动互联与通信技术 • 上一篇    下一篇

基于序列统计的未知无线协议特征提取方法

刘治国1,2, 蔡文珠1,2, 李运琪1,2, 潘成胜3   

  1. 1. 大连大学 信息工程学院, 辽宁 大连 116600;
    2. 大连大学 通信与网络重点实验室, 辽宁 大连 116600;
    3. 南京信息工程大学 电子与信息工程学院, 南京 211800
  • 收稿日期:2020-09-17 修回日期:2020-10-27 发布日期:2020-11-06
  • 作者简介:刘治国(1974-),男,教授、博士,主研方向为网络协议分析;蔡文珠、李运琪,硕士研究生;潘成胜,教授、博士。
  • 基金资助:
    国家自然科学基金(61931004)。

Feature Extraction Method for Unknown Wireless Protocol Based on Sequence Statistical

LIU Zhiguo1,2, CAI Wenzhu1,2, LI Yunqi1,2, PAN Chengsheng3   

  1. 1. School of Information Engineering, Dalian University, Dalian, Liaoning 116600, China;
    2. Key Laboratory of Communication and Network, Dalian University, Dalian, Liaoning 116600, China;
    3. School of Electronics and Information Engineering, Nanjing University of Information Science and Technology, Nanjing 211800, China
  • Received:2020-09-17 Revised:2020-10-27 Published:2020-11-06

摘要: 在未知无线网络环境下,比特流形式的协议数据帧特征不明显,且缺乏先验知识对其进行分析,造成特征提取困难。提出一种利用序列统计提取未知无线协议特征的方法。统计数据中定长序列出现的频次和位置,根据概率和相似性筛选满足频繁条件的固定序列和交互序列,得到频繁项集,并借鉴关联规则连接频繁项集中的频繁序列,去除冗余的序列信息,得到协议特征集。仿真结果表明,该方法能够有效提高未知无线协议特征提取效果,准确率稳定在90%以上。

关键词: 特征提取, 序列统计, 固定序列, 关联规则, 比特流

Abstract: In the unknown wireless network environment,the characteristics of data frames in the form of continuous bitstream are not obvious,and the lack of prior knowledge in data frame analysis poses difficulties for feature extraction.To address the problem,a feature extraction method for unknown wireless protocols is proposed based statistical analysis.The frequency and position at which the fixed-length sequences occur in the data are counted.On this basis,the fixed sequences and interactive sequences are filtered according to the probability and the similarity idea,and the ones that meet the frequency conditions are selected to obtain the frequent item set.Then the frequent sequences are connected according to the association rules to remove the redundant information.Simulation results show that this method can improve the feature extraction effect for unknown wireless protocols with the accuracy reaching over 90%.

Key words: feature extraction, sequence statistics, fixed sequence, association rule, bitstream

中图分类号: