节点文献
基于NetFPGA的网络流量分类
【作者】 李彬;
【导师】 张凤荔;
【作者基本信息】 电子科技大学 , 软件工程, 2011, 硕士
【摘要】 高性能的网络流量分类是诸多网络安全问题的基础。研究网络流量分类,既具有现实价值,又具有研究意义。论文基于NetFPGA网络可编程硬件平台研究网络流量分类技术,并实现基于NetFPGA的高速、准确、可靠的网络流量分类系统。NetFPGA是美国斯坦福大学开发设计的,为网络研究人员提供的,一个低成本可重用的网络硬件平台。其FPGA技术的应用使得平台既具有硬件的高速处理性能,又具备像软件一样可编程、重复使用的灵活性。本论文充分认识到现有流量分类技术速度性能、实时性、可扩展性等方面的不足,将NetFPGA硬件平台应用到网络流量分类系统中。在NetFPGA硬件上,系统实现基于主机行为的网络流量的信息收集、信息存储管理和流量控制等通过硬件实现的功能,并与软件结合实现高速、高效的网络流量分类。主机行为分析和网络流量统计特征分析是本论文网络流量分类的主要思想和方法。论文主机行为分析主要内容是IP地址和端口区分,将网络流量按照IP地址和端口进行归类,并收集流量的统计特征。流量统计特征分析选择快速、准确、高效朴素贝叶斯分类算法。在传统的朴素贝叶斯分类算法的基础上,学习训练过程中增加了后验概率的估算,并基于这种后验概率的估算技术设计了双阈值朴素贝叶斯分类器。改进后的分类器既能节约大量的计算资源,又能对新的网络流量进行主动识别,满足了高速网络流量分类的需求。测试结果表明:NetFPGA硬件和主机上分类器软件的结合,网络流量分类性能得到较大的提升。处理网速达700Mbps,分类算法节约计算资源40%以上,分类精度方面与决策树、神经网络、支持向量机等其它分类算法不相上下。
【Abstract】 High-performance network flow classification is the foundation of many cyber securities. The Research of flow classification has both real-life value and its research Significance. Based on network hardware platform NetFPGA, this paper investigated the skills of flow classification, and designed a flow classification system by platform NetFPGA.NetFPGA is designed by Standford, aimed at creating a cheap and reusable hardware platform for researchers of cyber realm. Taking advantage of the FPGA, NetFPGA not only has high speed of hardware, but also has programmable, reusable ability like software. This paper is aware of the shortcomings of current flow classification, which is snow, delaying and steadfast, and applies the NetFPGA to flow classification area. The NetFPGA’s works contain collecting flow information, saving information and controlling the network flow. It services to the classification software which works on the host PC of NetFPGA. The system has high-speed and high-performance ability.Analyzing host behavior of network and statistical feature of flow is critical mentality and main method of this thesis. The host behavior analysis contains dealing with IP address and port distinguishes, namely, categorizing network flow according to IP address and port. It also contains collecting packets and gathering the statistical feature of flow. Using machine learning technology, statistical feature analysis selects the fast, accurate and high-performance Naive Bayesian algorithm. This paper reforms the Naive Bayesian algorithm in the learning phase which supervised machine learning algorithm must contain. At end of the learning phase, it adds work to calculate posterior probability by flow training data. Based on the posterior probability, reforming algorithm saves a lot of calculating resources and has the ability of coping with high speed flow.The test results show that: combining NetFPGA with the reformed classifier, classification ability of the system has distinct improvement. The coping speed can be up to 700Mbps. The saved calculating resources can arrived at 40%. The test accurate parameters are similar to decision tree, neural net and SVM.
【Key words】 flow classification; NetFPGA; Naive Bayesian algorithm; posterior probability;
- 【网络出版投稿人】 电子科技大学 【网络出版年期】2011年 07期
- 【分类号】TP393.06
- 【被引频次】16
- 【下载频次】449