Summary of the invention
The technical problem to be solved in the present invention is to provide a kind of method and device of the P2P of detection flow, raisingTo the recognition efficiency of P2P flow.
The technical solution used in the present invention is that the method for described detection P2P flow, comprising:
Source host is monitored, active on the quantity of the destination host connecting according to source host and source hostThe quantity of session, judges whether source host possesses P2P feature.
The acquisition process of the quantity of the destination host that further, described source host connects is as follows:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
On described source host, the acquisition process of the quantity of active session is as follows:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, the described connection state information based on source host is determined session corresponding to each connectionActive degree, specifically comprises:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Further, active session on the quantity of the described destination host connecting according to source host and source hostQuantity, judge that whether source host possesses P2P feature, specifically comprises:
A1, is included into monitoring list by source host to be monitored;
A2, judges whether the quantity of the destination host of source host connection meets the Second Threshold of setting, if so,Perform step A3, otherwise repeated execution of steps A2 is to process the next source host in monitoring list;
A3, judges whether the quantity of active session on source host meets the 3rd threshold values of setting, and if so, willDescribed source host is judged to be to possess the main frame of P2P feature, otherwise repeated execution of steps A2 is to process monitoring listIn next source host.
Further, described method also comprises:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
The present invention also provides a kind of device of the P2P of detection flow, comprising:
Monitoring modular, for source host is monitored, obtain source host connect destination host quantity withAnd the quantity of active session on source host;
Judge module, for active session on the quantity of destination host that connects according to source host and source hostQuantity, judge whether source host possesses P2P feature.
Further, in the time obtaining the quantity of destination host of source host connection, described monitoring modular is specifically usedIn:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
In the time obtaining the quantity of active session on source host, described monitoring modular specifically for:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection;
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, in the time determining the active degree of session corresponding to each connection, also tool of described monitoring modularBody is used for:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Further, described monitoring modular, also for: source host to be monitored is included into monitoring list;
Described judge module, specifically comprises:
First judges submodule, sets for judging that whether the quantity of the destination host that source host connects meetSecond Threshold, if so, second judges submodule, otherwise repeats to call the first judgement submodule to process prisonSurvey the next source host in list;
Second judges submodule, whether meets the 3rd of setting for the quantity that judges active session on source hostThreshold values, if so, is judged to be described source host to possess the main frame of P2P feature, otherwise repeats to call firstJudge that submodule is to process the next source host in monitoring list.
Further, described judge module also for:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet.
Adopt technique scheme, the present invention at least has following advantages:
Method and the device of detection P2P flow of the present invention, with the existing industry based on DFI detection meansBusiness kind identification method is compared, and realizes simply, can be with less detection index, reach identical even higherAccuracy of detection, thereby mentioned the detection efficiency of P2P flow, shortened detection time.
The technical scheme of combination DPI detection means of the present invention, the identification that can also further improve P2P flowPrecision, than merely being used DPI detection means recognition efficiency to improve 70-80%, to more active application onlyNeed the extremely short time just can identify.
Detailed description of the invention
Technological means and effect of taking for reaching predetermined object for further setting forth the present invention, below knotClose accompanying drawing and preferred embodiment, the present invention is described in detail as after.
First embodiment of the invention, a kind of method that detects P2P flow, as shown in Figure 1, comprises following toolBody step:
Step S101, monitors source host, obtains quantity and the source of the destination host of source host connectionThe quantity of active session on main frame. When source host access destination host, initiate connection request to destination host,Destination host is for providing the main frame of downloaded resources.
Concrete, the acquisition process of the quantity of the destination host that source host connects is as follows:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
As shown in Figure 2, on source host, the acquisition process of the quantity of active session is as follows:
S1, the connection state information based on preserving on source host is determined the journey of enlivening of session corresponding to each connectionDegree. In the time that source host and destination host connect, on source host, conventionally can preserve connection state information,Such as, preserve every with the form of session table and connect related five-tuple information: source IP address, orderIP address, source port, destination interface and protocol information, this is the known technology of this area, soPlace is not described in detail. Step S1 specifically comprises:
S11: the active degree initial value that the session of timer, each connection correspondence is set;
S12: for arbitrary session, whenever time of timer then, judge whether described session exists dataTransmission, if so, increases a unit amount by active degree current described session, otherwise deducts oneUnit amount. The size of unit amount can arrange as required flexibly.
S2, when the active degree of session higher than set the first threshold values time, described session is judged to be to active meetingTalk about, count the quantity of active session on source host.
Step S102, the number of active session on the quantity of the destination host connecting according to source host and source hostAmount, judges whether source host possesses P2P feature.
Preferably, as shown in Figure 3, for multiple source hosts to be monitored, method is also wrapped described in the present embodimentDraw together as the implementation process that judges:
A1, is included into monitoring list by source host to be monitored;
A2, judges whether the quantity of the destination host of source host connection meets the Second Threshold of setting, if so,Perform step A3, otherwise repeated execution of steps A2 is to process the next source host in monitoring list;
A3, judges whether the quantity of active session on source host meets the 3rd threshold values of setting, and if so, willDescribed source host is judged to be to possess the main frame of P2P feature, otherwise repeated execution of steps A2 is to process monitoring listIn next source host.
Preferably, method described in the present embodiment also comprises after step S102:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification to packet, follow-upCan carry out corresponding strategy to the P2P flow identifying.
Second embodiment of the invention, a kind of device that detects P2P flow, as shown in Figure 4, comprises following groupBecome part:
Monitoring modular 100, for source host is monitored, obtains the quantity of the destination host of source host connectionAnd the quantity of active session on source host; When source host access destination host, initiate to connect to destination hostRequest, destination host is for providing the main frame of downloaded resources.
Judge module 200, for active meeting on the quantity of destination host that connects according to source host and source hostThe quantity of words, judges whether source host possesses P2P feature.
Concrete, in the time obtaining the quantity of the destination host that source host connects, monitoring modular 100 specifically for:
The IP address of the destination host by Statistic Source host access, determines the destination host that source host connectsQuantity;
In the time obtaining the quantity of active session on source host, monitoring modular 100 specifically for:
Connection state information based on preserving on source host is determined the active degree of session corresponding to each connection.In the time that source host and destination host connect, on source host, conventionally can preserve connection state information; ThisThe known technology of this area, so locate not describe in detail.
When the active degree of session higher than set the first threshold values time, described session is judged to be to active session,Count the quantity of active session on source host.
Further, in the time determining the active degree of session corresponding to each connection, also tool of monitoring modular 100Body is used for:
The active degree initial value of the session of timer, each connection correspondence is set;
For arbitrary session, whenever time of timer then, judge whether described session exists transfer of data,If so, active degree current described session is increased to a unit amount, otherwise deduct a unitsValue.
Preferably, as shown in Figure 5, for multiple source hosts to be monitored, that installs described in the present embodiment is eachModule also comprises following function and implementation:
Monitoring modular 100, also for: source host to be monitored is included into monitoring list;
Judge module 200, specifically comprises:
Whether first judges submodule 201, meet and set for the quantity that judges the destination host that source host connectsSecond Threshold, if so, second judge submodule, otherwise repeat to call the first judgement submodule to processNext source host in monitoring list;
Second judges submodule 202, for judge the quantity of active session on source host whether meet set theThree threshold values, if so, are judged to be described source host to possess the main frame of P2P feature, otherwise repeat to callOne judges that submodule is to process the next source host in monitoring list.
It should be noted that, in the embodiment of the present invention, quantity and the source host of the destination host that source host connectsThe quantity of upper active session is two features that must judge, the present invention does not limit these two featuresJudgement order, that is to say, is not limited to the quantity of the destination host that first judges source host connection, also can be firstJudge the quantity of active session on source host.
Preferably, described in the present embodiment device in, described judge module also for:
In the time judging that source host possesses P2P feature, the connection state information based on preserving on source host filters outWith the packet of each join dependency, adopt DPI detection method to carry out type of service identification (to knowing to packetThe P2P flow not going out is carried out corresponding strategy).
Based on above-described embodiment, introduce an application example of the present invention below:
Application example of the present invention is that some behavioural characteristic values of network traffics are added up, according to the knot of statisticsFruit judges whether to possess P2P feature. The behavioural characteristic of statistics comprises following two aspects:
Feature 1: certain source host connects destination host quantity;
Feature 2: the quantity of the current active session of certain source host;
When feature 1 and feature 2 all reach the threshold values of setting, this main frame is considered to possess the master of P2P featureMachine.
Active session refers to that transmission data are than session more frequently, and the time of transmitting is continuously longer, active degreeHigher. The active degree of session, is defined as follows:
The initial value of session active degree is set as 0;
In a given timer time interval T, if session has transfer of data, at timer time TWhen end, the active degree value of this session adds 1, otherwise subtracts 1, and active degree value is minimum reduces to 0;
If the active degree value of session is greater than the first given threshold values, this session is exactly active session; FirstThe scope of threshold values can be 3~5, and preferred, the first threshold values is 4.
Fig. 6 is session active degree calculated examples schematic diagram, and as shown in Figure 6, arrow is illustrated in two timesIn point, (being in a time interval T of timer) has flow process, in T0, T1, T2, T3 moment,The active degree of session is respectively:
The active degree of session A is (0,1,2,3)
The active degree of session B is (0,1,0,1)
The active degree of session C is (0,1,0,0)
The thinking of application example of the present invention is mainly from flow, to extract feature, and traffic characteristic comprises that source host connectsThe quantity of the destination host connecing, the quantity of the active session of source host. Adopt DFI and DPI function synergic pairThe scheme that P2P flow is identified, and the main frame that possesses P2P feature to identifying proposed solution,Specifically comprise following process:
Step 1, user sets the source host scope that needs monitoring;
Step 2, arranges a timer, completes once to all monitored source hosts every a time cycleScanning, scanning process is as follows:
B21, detects the destination host number being connected with source host and whether is greater than the first specified threshold, if be greater than,Proceed scanning process below, otherwise, next main frame is scanned; The first specified threshold canThink 32-64, preferably 48.
B22, to source host, all sessions are carried out the calculating of active degree and are judged active session, if activeNumber of sessions is greater than the source host of the second specified threshold, is identified as the main frame that possesses P2P feature; SecondSpecified threshold can be 10~29, preferably 16.
Step 3, the session table of main frame based on possessing P2P feature filters out the data with each join dependencyBag, carries out type of service identification by DPI detection means to packet, if determine its type of service,Take corresponding strategy to process, if can not determine type of service, show the company at this packet placeIt is undesired to connect, and blocks this connection.
In the step 2 of this application example, mention timing, the time interval of monitoring is set, this time interval canWith with statistics session active degree time timer used the time interval identical, it is same fixed to adoptTime device. The number range in the time interval of this timer is 5~10 seconds, preferred, between the time of this timerBe divided into 8 seconds.
Application example of the present invention, the technical scheme that adopts DFI to combine with DPI, can fine identification P2PFlow, has improved 70-80% than the recognition efficiency that merely uses DPI detection means, should to relatively more activeJust can identify with the time cycle that only needs several timers.
By the explanation of detailed description of the invention, the technology that should take for reaching predetermined object the present inventionMeans and effect are able to more deeply and concrete understanding, but appended diagram is only to provide with reference to explanationWith, be not used for the present invention to be limited.