节点文献
基于流特征的P2P流量检测方法研究
Research on P2P Traffic Detection Based on Flow Characteristics
【作者】 姜伟;
【导师】 王春枝;
【作者基本信息】 湖北工业大学 , 计算机应用技术, 2010, 硕士
【摘要】 近几年来伴随网络技术的发展,P2P技术已经得到了广泛的应用,据调查,P2P应用产生的网络流量己占据ISP业务总量的60%-90%,严重影响了正常的网络业务,甚至引起网络拥塞。而且对其它正常的网络服务,如Web、FTP、Email等的性能造成极大的影响。通常网络流量的识别可以通过端口、协议或流量特征等方法进行识别,例如:80端口的TCP流为HTTP流,21端口的UDP流为FTP流。但是,随着Internet网络的不断发展,由于很多新兴的网络服务(如P2P、在线游戏等)开始采用随机选取端口、协议加密等原因,使得传统的基于端口(Port)的流量分类和基于有效载荷(Payload)的识别方法已不能保证进行正确的网络流量分类。本文对现有的P2P流量识别方法进行了对比研究,在此基础上做了如下工作:1、研究了当前几种P2P流量检测控制模型的工作原理,以及其在识别过程中存在的优缺点。2、通过实验提取P2P流量的上/下行流量比,平均流速率,平均数据包长度,流持续时间,传输字节数、端口变化率、包大小变化率、TCP/UDP协议包比等八个特征作为识别P2P流量的特征参数。3、提出一种基于流特征的P2P流量检测控制模型,介绍该模型的理论基础。4、设计并实现了基于流特征的P2P流量检测控制模型,并介绍了模型的总体设计架构和实现机制,详细说明了该模型的组成模块。5、在实际的网络环境中对该模型的识别性能进行了测试,并对实验数据进行分析与评价。本学位论文得到湖北省自然基金项目(2009CDB100)的资助。
【Abstract】 With the development of network technology in recent years, the P2P technology has been widely applied. According to investigation, network traffic generated by P2P application has accounted for 60%-90% of ISP services, seriously affecting normal network service such as Web、FTP、Email, as well as resulting in network congestion.The P2P traffic can be identified by port, protocol and traffic character, namely, the TCP flow of 80 port is HTTP flow traffic, and the UDP flow of 21 port is FTP flow. However, with the increasing development of network technology, lots of newly arisen network services like P2P and online games have began to choose port at random and encrypt protocol. Thus traditional traffic classification based on port and identification method based on payload can not make sure to classify network traffic correctly any more.The paper researched on existing methods of P2P traffic identification and made a comparison, and did some work as follows:1、Researching on working principle of existing P2P traffic detection controlling models, as well as advantages and disadvantages existing in identification process.2、Extracted through experiments P2P traffic up/downstream traffic ratio, the average flow rate, the average packet length, flow duration, number of bytes transferred, the port changes in the rate of change in the rate of packet size, TCP/UDP protocol packets than the other eight features as identify the P2P traffic characteristic parameters.3、Proposing a P2P traffic detection controlling model based on flow characteristics and introducing its theoretical basis.4、Designing and implementing the prototype system of the P2P traffic detection controlling model based on flow characteristics, introducing general design and realization mechanism of the system as well as functions of each component modules.5、Testing identification ability of the model in actual network environment, analyzing and evaluating of the test data.The dissertation is supported by Hubei province natural fund project of 2009CDB100.