作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (24): 91-93. doi: 10.3969/j.issn.1000-3428.2011.24.030

• 网络与通信 • 上一篇    下一篇

基于GMM的ESP流量应用层协议识别

王庆龙,王振兴,张连成,王 禹   

  1. (解放军信息工程大学信息工程学院,郑州 450002)
  • 收稿日期:2011-05-23 出版日期:2011-12-20 发布日期:2011-12-20
  • 作者简介:王庆龙(1982-),男,硕士研究生,主研方向:网络与信息安全;王振兴,教授、博士生导师;张连成、王 禹,博士研究生

GMM-based Application-layer Protocol Identification of ESP Traffic

WANG Qing-long, WANG Zhen-xing, ZHANG Lian-cheng, WANG Yu   

  1. (College of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China)
  • Received:2011-05-23 Online:2011-12-20 Published:2011-12-20

摘要: 提出一种高斯混合模型的ESP流量应用层协议识别技术,采用同步采集和流量模拟2种方式构造ESP数据集,建立HTTP、FTP、SMTP和TELNET 4种协议的ESP流量高斯混合模型,并对该模型进行测试,结果表明,高斯混合模型对ESP流量具有较好的协议识别能力,可利用ESP流量的网络层特征识别其应用层协议。

关键词: IP安全, ESP流量, 高斯混合模型, 流量分析, 协议识别

Abstract: This paper proposes a GMM-based application-layer protocol identification technique of ESP traffic. It uses two means to construct the ESP traffic data sets, one is synchronous collection, another is traffic simulation, And builds and tests the GMMs of HTTP, FTP, SMTP and TELNET on the data sets. Result shows GMM is applicable to identify the application-layer protocol of the ESP traffic, and the network-layer characteristics of the ESP traffic leak enough information to identify other application-layer protocol.

Key words: IPSec, ESP traffic, Gaussian Mixture Model(GMM), traffic analysis, protocol identification

中图分类号: