首页> 外文OA文献 >Analyzing Network Protocols of Application Layer Using Hidden Semi-Markov Model
【2h】

Analyzing Network Protocols of Application Layer Using Hidden Semi-Markov Model

机译:使用隐藏半马尔可夫模型分析应用层网络协议

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With the rapid development of Internet, especially the mobile Internet, the new applications or network attacks emerge in a high rate in recent years. More and more traffic becomes unknown due to the lack of protocol specifications about the newly emerging applications. Automatic protocol reverse engineering is a promising solution for understanding this unknown traffic and recovering its protocol specification. One challenge of protocol reverse engineering is to determine the length of protocol keywords and message fields. Existing algorithms are designed to select the longest substrings as protocol keywords, which is an empirical way to decide the length of protocol keywords. In this paper, we propose a novel approach to determine the optimal length of protocol keywords and recover message formats of Internet protocols by maximizing the likelihood probability of message segmentation and keyword selection. A hidden semi-Markov model is presented to model the protocol message format. An affinity propagation mechanism based clustering technique is introduced to determine the message type. The proposed method is applied to identify network traffic and compare the results with existing algorithm.
机译:随着互联网的快速发展,尤其是移动互联网,近年来,新的应用或网络攻击的速度很高。由于关于新出现的应用程序缺乏协议规范,越来越多的流量变得未知。自动协议逆向工程是理解该未知流量并恢复其协议规范的有希望的解决方案。协议逆向工程的一个挑战是确定协议关键字和消息字段的长度。现有算法被设计为选择最长的子网格作为协议关键字,这是决定协议关键字长度的经验方式。在本文中,我们提出了一种新的方法来确定协议关键字的最佳长度,并通过最大化消息分割和关键字选择的似然概率来恢复因特网协议的消息格式。提出了一个隐藏的半Markov模型以绘制协议消息格式。引入了基于相关的基于聚类机制的聚类技术来确定消息类型。应用方法用于识别网络流量并将结果与​​现有算法进行比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号