节点文献

网络入侵中未知协议识别单元的设计与测试

Design and testing of recognition unit for Unknown protocols in network intrusion

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 芦彩林邹恒何淑贤

【Author】 LU Cailin;ZOU Heng;HE Shuxian;School of Information Technology and Engineering,Jinzhong University;Shaanxi Provincial Supervision and Inspection Institute of Electronic Information Products;

【机构】 晋中学院信息技术与工程学院陕西省电子信息产品监督检验院

【摘要】 为了提高复杂环境下的网络安全性,设计并实现了一种网络入侵中未知协议识别单元。系统通过网络入侵检测模块对网络入侵进行检测并过滤,使得未知协议识别单元的设计不受网络入侵的干扰。利用流量采集模块对网络节点的网络流量进行采集,为后续阶段提供完整的网络数据包以及充分的数据分析样本,将采集的网络数据包以指针的形式返回,发送至流量调度模块。通过流量调度模块将网络数据包的源IP地址作为调度参数,依据用户自定义调度算法将网络数据包传输至指定识别模块,实现整个网络入侵中未知协议识别单元的负载均衡。利用规则匹配模块将从流量调度模块接收到的信息和协议特征库进行匹配,从而实现未知协议的识别。软件设计过程中,对网络入侵中未知协议识别单元进行了详细分析,并给出了网络入侵中未知协议识别的程序代码。仿真实验结果验证了该系统的可行性和实用性。

【Abstract】 In order to improve the network security in a complicated environment,an identification unit for unknown protocols in network intrusion was designed and realized. System detects and filters network intrusion through the network intrusion detection module to make the unknown protocol identification unit unaffected by the interference of network intrusion. The network traffic of the network nodes is collected by traffic acquisition module,which provides complete network data packets and sufficient data analysis samples for later stages,and returns the collected network data packets in the pointer form and sends to the traffic scheduling module. The source IP address of the network data packets is taken as scheduling parameters through traffic scheduling module. The network data packets are transmitted to the assigned identification module according to the user-defined scheduling algorithm to realize the load balancing of unknown protocol identification unit in the whole network intrusion.the information received by traffic scheduling module is matched with the protocol characteristic library by means of the rule matching module,so as to realize the identification of unknown protocol. In the process of software design,the recognition unit of unknown protocol in network intrusion are analyzed in detail. The program code for unknown protocol recognition in network intrusion is offered. The feasibility and practicability of the system were verified by simulation experiment.

【基金】 网络环境下大学物理仿真实验教学改革与实践(J2014108)
  • 【文献出处】 现代电子技术 ,Modern Electronics Technique , 编辑部邮箱 ,2015年22期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】72
节点文献中: 

本文链接的文献网络图示:

本文的引文网络