面向比特流的鏈路協(xié)議識(shí)別與分析技術(shù)
[Abstract]:In the communication environment of military and commercial fields, it is necessary to monitor the communication for the sake of security, and protocol identification is one of the main methods. The technology of detecting high layer protocol is mature, but the research of protocol identification in link layer is rare. However, in the fields of wireless channel monitoring, electronic countermeasure, satellite communication, etc., the data link layer protocol is recognized. Frame cutting technology has practical requirements. The difficulty of link protocol identification and analysis is that the target data is bit stream, and the specificity of character set seriously restricts the efficiency of recognition and analysis. At present, there are many link layer protocols, most of which have non-public frame format definition, so how to cut the bitstream of unknown data link layer is another difficult problem. In this paper, the technology of link layer protocol identification and analysis for bit-stream is studied, and the two difficult problems mentioned above are emphatically studied, and their respective solutions are put forward. 1) how to improve the efficiency of analysis and identification of typical link layer protocols. It is found that the bottleneck of the efficiency is the pattern matching algorithm, which is because these classical algorithms are not suitable for the bitstream scene. Based on the idea of classical QS (quick search) algorithm and the characteristics of bit stream, a coding QS algorithm is proposed for the special scene in this paper. Experiments show that the algorithm is effective and its advantages are illustrated by comparison with other schemes. 2) how to extract frames when the format of link protocol is completely unknown. In this paper, a bit stream cutting algorithm based on data mining is proposed. Firstly, the structure of the protocol frame and the association characteristics in the frame are analyzed. Then, the feature sequence and the association rule sequence marking the start of the frame are extracted by frequent statistics and association rule verification. According to the threshold N of the number of results set by the user, the most probable cutting scheme can be given. The effectiveness and robustness of the algorithm are verified by real data test.
【學(xué)位授予單位】:中國科學(xué)技術(shù)大學(xué)
【學(xué)位級(jí)別】:碩士
【學(xué)位授予年份】:2014
【分類號(hào)】:TN915.04
【參考文獻(xiàn)】
相關(guān)期刊論文 前10條
1 賀培港;;一種新型的網(wǎng)絡(luò)協(xié)議分析模型[J];電腦與電信;2011年02期
2 姚秀娟;李雪;;CCSDS空間鏈路層協(xié)議識(shí)別技術(shù)研究[J];航天電子對(duì)抗;2012年02期
3 王永成,沈州,許一震;改進(jìn)的多模式匹配算法[J];計(jì)算機(jī)研究與發(fā)展;2002年01期
4 唐謙,張大方;入侵檢測(cè)中模式匹配算法的性能分析[J];計(jì)算機(jī)工程與應(yīng)用;2005年17期
5 李雄偉;王希武;王盼卿;;基于模式串匹配的Ethernet協(xié)議識(shí)別算法研究[J];計(jì)算機(jī)工程與應(yīng)用;2007年29期
6 陳亮;龔儉;徐選;;應(yīng)用層協(xié)議識(shí)別算法綜述[J];計(jì)算機(jī)科學(xué);2007年07期
7 楊武,方濱興,云曉春,張宏莉;入侵檢測(cè)系統(tǒng)中高效模式匹配算法的研究[J];計(jì)算機(jī)工程;2004年13期
8 宋疆;張春瑞;張楠;李芬;吳艷梅;;基于數(shù)據(jù)報(bào)指紋關(guān)系的未知協(xié)議識(shí)別與發(fā)現(xiàn)[J];計(jì)算機(jī)應(yīng)用研究;2012年12期
9 許家銘;李曉東;金鍵;馬盈;;一種高效的多模式字符串匹配算法[J];計(jì)算機(jī)工程;2014年03期
10 巫喜紅;;改進(jìn)的QS模式匹配算法的性能分析[J];計(jì)算機(jī)工程與應(yīng)用;2014年02期
,本文編號(hào):2335878
本文鏈接:http://sikaile.net/kejilunwen/wltx/2335878.html