Abstract:
Based on timing analysis of network sessions, this paper puts forward a detection approach of heartbeat packet sequence based on clustering processing. It processes the network data stream with time clustering, expands the cluster collection by periodic features, and screens out the clusters which do not meet the characteristics, and detects the heartbeat packet sequence within steady cluster collection. Experimental results show that this approach can achieve higher correct detection rate, real-time detection and processing.
Key words:
periodic sequence,
heartbeat packet,
clustering,
heartbeat packet detection,
network synchronous
摘要: 在对网络会话进行时序分析的基础上,提出基于数据流分簇处理的心跳包序列检测方法。对数据流进行时序分簇处理,按周期性特征扩充簇集合,筛除不符合特征的簇对象,根据稳定的簇集合检测心跳包序列。实验结果表明,该方法检测率较高、误检率较低,能够实现实时检测和处理。
关键词:
周期性序列,
心跳包,
分簇,
心跳包检测,
网络同步
CLC Number:
YI Jun-Kai, CHEN Li, SUN Jian-Wei. Data Flow Clustering Detection Approach of Network Heartbeat Packet Sequence[J]. Computer Engineering, 2011, 37(24): 61-63.
易军凯, 陈利, 孙建伟. 网络心跳包序列的数据流分簇检测方法[J]. 计算机工程, 2011, 37(24): 61-63.