Computer Engineering and Applications ›› 2010, Vol. 46 ›› Issue (14): 91-94.DOI: 10.3778/j.issn.1002-8331.2010.14.027

• 网络、通信、安全 • Previous Articles     Next Articles

Research of Bloom filter application in network forensics

ZHAO Qian,CUI Yi-min,ZOU Tao   

  1. Beijing Institute of System Engineering,Beijing 100101,China
  • Received:2008-11-07 Revised:2008-12-22 Online:2010-05-11 Published:2010-05-11
  • Contact: ZHAO Qian

Bloom filter在网络取证中的应用研究

赵 骞,崔益民,邹 涛   

  1. 北京系统工程研究所,北京 100101
  • 通讯作者: 赵 骞

Abstract: Aiming at technical challenges of traditional network forensics,this paper researches the trait of Bloom filter.A network forensics system based on Bloom filter is proposed and designed.Making use of the characteristics of Bloom filter data structure,the system can collect,compress and store the raw network data,so that the storage space is efficiently saved and post-event querying and analyzing is supported.At last some advices about future works are given.

Key words: network security, network forensics, Bloom filter

摘要: 针对传统网络取证技术的特点和技术挑战,对Bloom filter的特性进行了分析研究,设计了基于Bloom filter的网络取证系统。该系统利用Bloom filter数据结构的特点,能够实时对网络原始数据进行采集、压缩、存储,有效节省存储空间,支持高效的网络取证事后分析查询。最后指出了进一步的研究方向。

关键词: 网络安全, 网络取证, Bloom filter

CLC Number: