首页> 外文会议>Ural Symposium on Biomedical Engineering, Radioelectronics and Information Technology >Statistical-Entropy Method for Zero Knowledge Network Traffic Analysis Algorithm Implementation
【24h】

Statistical-Entropy Method for Zero Knowledge Network Traffic Analysis Algorithm Implementation

机译:零知识网络流量分析的统计熵方法实现

获取原文

摘要

The article is devoted to traffic analysis with zero knowledge about its structure. As a result of combining existing entropy and statistical algorithms, a statistical-entropy method has been developed capable of distinguishing network nodes and significant fields from traffic with unknown protocol. The decision about significant fields boundaries in the analyzed traffic sample made by the algorithm is based on the entropy of individual bytes and byte pairs mutual information. The statistical algorithm determines network addresses using estimate number of occurrences parts of a network packet similar (as a strings) to parts of a previously received array of network traffic. The mathematical models each of the algorithms are implemented as a module of the program that implements the statistical-entropy method. As a result of the software implementation of the described statistical-entropy method, network addresses are allocated from the network traffic with zero knowledge about the protocols used in it, and separation into semantic fields is proposed.
机译:本文专门介绍流量分析,但对其结构的了解为零。由于结合了现有的熵和统计算法,因此开发出了一种统计熵方法,该方法能够区分网络节点和重要字段与协议未知的流量。该算法根据所分析的流量样本中有关有效字段边界的决定是基于单个字节和字节对互信息的熵的。统计算法使用与先前接收到的网络流量阵列的部分相似(作为字符串)的网络数据包的出现部分的估计数目来确定网络地址。每个算法的数学模型都作为实现统计熵方法的程序模块来实现。作为所描述的统计熵方法的软件实现的结果,从网络流量中分配网络地址,并且其中所使用的协议的知识为零,并提出了将其分离为语义字段的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号