计算机工程与应用 ›› 2018, Vol. 54 ›› Issue (17): 95-102.DOI: 10.3778/j.issn.1002-8331.1705-0319

• 网络、通信与安全 • 上一篇    下一篇

具有抗噪性能的协议分类特征研究

徐正国,姚佳奇,郑  辉   

  1. 盲信号处理国家重点实验室,成都 610041
  • 出版日期:2018-09-01 发布日期:2018-08-30

Research on anti-noise features of network protocol classification

XU Zhengguo, YAO Jiaqi, ZHENG Hui   

  1. State Key Laboratory of Blind Signals Processing, Chengdu 610041, China
  • Online:2018-09-01 Published:2018-08-30

摘要: 针对未加密条件下的协议分类问题,研究了具有抗噪能力的协议特征构造方法。利用局部敏感哈希算法,筛选出协议样本数据中高频相似的数据片段,在此基础上提出了一种能够反映协议数据取值分布固有属性的协议特征。相比于基于协议流量统计测量的外部特征,协议数据内容的内在特征不易受到网络传输环境的干扰。采用多种典型分类器对该特征的分类性能进行实验验证,结果表明协议分类的准确率大多能达到80%以上,在有噪声干扰的仿真测试条件下,该特征表现出较好的分类抗噪性能。

关键词: 协议分类, 抗噪, 协议特征, 局部敏感哈希, 多分类, 网络协议

Abstract: Towards the protocol classification problem in unencrypted network environment, a feature construction method with antinoise capability is studied. Using the local sensitive hashing algorithm, the fragments of high frequency in protocol data are extracted, which can reflect the inherent characteristics of the protocol data. The inherent characteristics are less susceptible to the network transmission than the external features based on the protocol traffic statistics. The experimental results show that the accuracy of protocol classification can achieve over 80% by taking advantage of the proposed feature, while the classification performance of this feature is not influenced much in the noisy environment.

Key words: protocol classification, antinoise, protocol feature, locality sensitive hashing, multi-classification, network protocol