计算机工程与应用 ›› 2009, Vol. 45 ›› Issue (27): 92-95.DOI: 10.3778/j.issn.1002-8331.2009.27.028

• 网络、通信、安全 • 上一篇    下一篇

一种基于行为模式的Skype流量识别方法

吴 伟,龙 翔,高小鹏   

  1. 北京航空航天大学 计算机学院,北京 100083
  • 收稿日期:2008-05-22 修回日期:2008-10-09 出版日期:2009-09-21 发布日期:2009-09-21
  • 通讯作者: 吴 伟

Identification method of Skype traffic based on behavior mode

WU Wei,LONG Xiang,GAO Xiao-peng   

  1. Department of Computer,Beihang University,Beijing 100083,China
  • Received:2008-05-22 Revised:2008-10-09 Online:2009-09-21 Published:2009-09-21
  • Contact: WU Wei

摘要: Skype是一种基于P2P技术的VoIP客户端,其通讯协议不公开,且通讯内容加密,因此对Skype的流量识别不能采用传统的端口识别法及特征字检测法。首先对Skype的通信机制进行深入的探讨,并通过实际的数据包分析总结出Skype流量的行为模式,最后设计并实现了相应的识别模块对结论进行验证。

关键词: P2P, 流量识别, 行为模式

Abstract: Skype is a kind of VoIP client based on P2P technology.Its communication protocol is secret,and the communication content is encrypted,so the traditional methods such as port-based method and signature-based method are not applicable for Skype traffic identification.This paper first gives the analysis of Skype communication mechanism in detail,then proposes the behavior mode of Skype traffic through packets analysis.Finally,an identification module is design and implemented to test the conclusion.

Key words: P2P, traffic identification, behavior mode

中图分类号: