首页 | 本学科首页   官方微博 | 高级检索  
     

基于相似度匹配的网络协议语法分析方法
引用本文:郭亮,罗森林,潘丽敏. 基于相似度匹配的网络协议语法分析方法[J]. 北京理工大学学报, 2016, 36(5): 520-523. DOI: 10.15918/j.tbit1001-0645.2016.05.015
作者姓名:郭亮  罗森林  潘丽敏
作者单位:北京理工大学信息系统及安全对抗实验中心, 北京 100081
基金项目:北京理工大学科技创新计划重大项目(2011CX01015);国家"二四二"计划项目(2005C48)
摘    要:为解决网络协议语法分析方法中,依赖人工干预、分析效率低下、分析范围较小等问题,提出一种基于相似度匹配的网络协议语法分析方法.通过嗅探采集网络原始数据包,解析基础协议并对数据包进行预处理,提取9维不同角度的特征,建立了网络协议语法相似分析模型,分析网络协议细节语法特征.通过将TCP协议作为已知协议,对UDP、DNS、QQ等3种不同类型的协议测试,结果表明这3类协议报头中,33%以上的字段能在TCP协议中找到对应的相似语法,而且平均准确率均在96%以上,该方法不需人工干预,可以提高分析效率、减少限制条件、扩大分析范围,并能较为有效地分析出网络协议语法特征. 

关 键 词:协议语法分析   协议逆向   相似度匹配
收稿时间:2014-03-24

Analysis of the Network Protocol Syntax Based on Similarity Matching
GUO Liang,LUO Sen-lin and PAN Li-min. Analysis of the Network Protocol Syntax Based on Similarity Matching[J]. Journal of Beijing Institute of Technology(Natural Science Edition), 2016, 36(5): 520-523. DOI: 10.15918/j.tbit1001-0645.2016.05.015
Authors:GUO Liang  LUO Sen-lin  PAN Li-min
Affiliation:Information System and Security & Countermeasures Experimental Center, Beijing Institute of Technology, Beijing 100081, China
Abstract:To solve the problems in analysis of the network protocol syntax, which are rely on human intervention, low efficiency and narrow scope, a method was proposed for analysis of network protocol syntax based on similarity matching. The main process of the method include collecting the raw packets by network sniffer, and then preprocessing the packets, using a variety of methods for 9 features extraction, establishing a network protocol syntax analysis model based on similarity matching method, to analyze the syntax feature of network protocol. Taking the TCP protocol as a known protocol, experiments were actualized with different types of protocols as UDP, DNS and QQ. The results show that in the three types of protocol header, more than 33% of the correct similar syntax fields can be found in TCP protocol, and the average accuracy rate was over 96%, the process needs not manual intervention, it can improve the analysis efficiency, reduce the constraints, expand the scope of the analysis, and analyze the network protocol syntax more effectively.
Keywords:analysis of the network protocol syntax  protocol reverse  similarity matching
本文献已被 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号