CN103312565B - 一种基于自主学习的对等网络流量识别方法 - Google Patents
一种基于自主学习的对等网络流量识别方法 Download PDFInfo
- Publication number
- CN103312565B CN103312565B CN201310262848.7A CN201310262848A CN103312565B CN 103312565 B CN103312565 B CN 103312565B CN 201310262848 A CN201310262848 A CN 201310262848A CN 103312565 B CN103312565 B CN 103312565B
- Authority
- CN
- China
- Prior art keywords
- message
- dfi
- dpi
- flow
- packet
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 43
- 230000004907 flux Effects 0.000 title claims abstract description 17
- 238000010801 machine learning Methods 0.000 claims abstract description 13
- 238000001514 detection method Methods 0.000 claims description 23
- 230000006870 function Effects 0.000 claims description 11
- 238000012360 testing method Methods 0.000 claims description 7
- 230000005540 biological transmission Effects 0.000 claims description 5
- 238000005516 engineering process Methods 0.000 abstract description 28
- 238000004458 analytical method Methods 0.000 description 7
- 238000012549 training Methods 0.000 description 7
- 238000004891 communication Methods 0.000 description 5
- 238000003066 decision tree Methods 0.000 description 5
- 238000000605 extraction Methods 0.000 description 5
- 230000008569 process Effects 0.000 description 5
- 230000008901 benefit Effects 0.000 description 4
- 230000003542 behavioural effect Effects 0.000 description 2
- 230000007246 mechanism Effects 0.000 description 2
- 238000012706 support-vector machine Methods 0.000 description 2
- 230000006399 behavior Effects 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000000903 blocking effect Effects 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000000205 computational method Methods 0.000 description 1
- 230000008878 coupling Effects 0.000 description 1
- 238000010168 coupling process Methods 0.000 description 1
- 238000005859 coupling reaction Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000004069 differentiation Effects 0.000 description 1
- 238000001914 filtration Methods 0.000 description 1
- 230000008676 import Effects 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 230000002045 lasting effect Effects 0.000 description 1
- 239000000203 mixture Substances 0.000 description 1
- 230000006855 networking Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
Abstract
Description
DPI | DFI | |
概念 | 针对数据包的净载荷进行深入分析、对比 | 是一种基于流量行为的应用识别技术,主要针对P2P流量与其他流量之间的不同特征,来确定是否是P2P流 |
精确度 | 高 | 低 |
出错率 | 低 | 较高 |
识别代价 | 较高 | 低 |
可扩展性 | 窄,适应性差,只针对特定协议 | 宽,适应性好,可以识别多种协议 |
协议分类 | 好 | 无法分类 |
识别速度 | 较慢 | 快 |
实时性 | 很好 | 好 |
Claims (1)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310262848.7A CN103312565B (zh) | 2013-06-28 | 2013-06-28 | 一种基于自主学习的对等网络流量识别方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310262848.7A CN103312565B (zh) | 2013-06-28 | 2013-06-28 | 一种基于自主学习的对等网络流量识别方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN103312565A CN103312565A (zh) | 2013-09-18 |
CN103312565B true CN103312565B (zh) | 2015-12-23 |
Family
ID=49137366
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201310262848.7A Active CN103312565B (zh) | 2013-06-28 | 2013-06-28 | 一种基于自主学习的对等网络流量识别方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN103312565B (zh) |
Families Citing this family (17)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN104579805A (zh) * | 2013-10-12 | 2015-04-29 | 郑州冰川网络技术有限公司 | 一种新的网络流量识别方法 |
CN104702460A (zh) * | 2013-12-10 | 2015-06-10 | 中国科学院沈阳自动化研究所 | 基于SVM的Modbus TCP通讯的异常检测方法 |
CN104052639B (zh) * | 2014-07-02 | 2017-03-22 | 山东大学 | 基于支持向量机的实时多应用网络流量识别方法 |
WO2017061895A1 (en) * | 2015-10-09 | 2017-04-13 | Huawei Technologies Co., Ltd. | Method and system for automatic online identification of network traffic patterns |
CN105429817A (zh) * | 2015-10-30 | 2016-03-23 | 中兴软创科技股份有限公司 | 基于dpi和dfi的非法业务识别装置与方法 |
CN106453434A (zh) * | 2016-12-20 | 2017-02-22 | 北京启明星辰信息安全技术有限公司 | 一种网络流量的监测方法及监测系统 |
CN107682317B (zh) * | 2017-09-06 | 2019-12-06 | 中国科学院计算机网络信息中心 | 建立数据检测模型的方法、数据检测方法及设备 |
CN109104381B (zh) * | 2018-06-26 | 2021-11-02 | 东南大学 | 一种基于第三方流量http报文的移动应用识别方法 |
CN110838948B (zh) * | 2018-08-15 | 2022-02-22 | 迈普通信技术股份有限公司 | 测试mac地址学习速率的方法、测试系统 |
CN109639655A (zh) * | 2018-11-30 | 2019-04-16 | 南京中新赛克科技有限责任公司 | 一种智能深度解析系统及解析方法 |
CN109951444B (zh) * | 2019-01-29 | 2020-05-22 | 中国科学院信息工程研究所 | 一种加密匿名网络流量识别方法 |
CN109756512B (zh) * | 2019-02-14 | 2021-08-13 | 深信服科技股份有限公司 | 一种流量应用识别方法、装置、设备及存储介质 |
CN111988239B (zh) * | 2020-08-21 | 2022-07-15 | 哈尔滨工业大学 | 一种用于Android应用的软件纯净流量获取方法 |
CN112235160B (zh) * | 2020-10-14 | 2022-02-01 | 福建奇点时空数字科技有限公司 | 一种基于协议数据深层检测的流量识别方法 |
CN112383489A (zh) * | 2020-11-16 | 2021-02-19 | 中国信息通信研究院 | 一种网络数据流量转发方法和装置 |
CN113301049B (zh) * | 2021-05-26 | 2023-02-24 | 杭州安恒信息技术股份有限公司 | 一种工控设备的审计方法、装置、设备及可读存储介质 |
CN113965526A (zh) * | 2021-09-18 | 2022-01-21 | 网宿科技股份有限公司 | 数据处理方法、电子设备及计算机可读存储介质 |
Citations (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101599897A (zh) * | 2009-06-10 | 2009-12-09 | 南京邮电大学 | 一种基于应用层检测的对等网络流量控制方法 |
CN101741744A (zh) * | 2009-12-17 | 2010-06-16 | 东南大学 | 一种网络流量识别方法 |
CN101764754A (zh) * | 2009-12-28 | 2010-06-30 | 东南大学 | 基于dpi和dfi的业务识别系统中的样本获取方法 |
CN102185758A (zh) * | 2011-04-08 | 2011-09-14 | 南京邮电大学 | 一种基于阿瑞斯报文特征字的协议识别方法 |
KR20120067528A (ko) * | 2010-12-16 | 2012-06-26 | 엘지에릭슨 주식회사 | 규칙 자기 학습 방법 및 그를 위한 lte 시스템 |
CN102571946A (zh) * | 2011-12-28 | 2012-07-11 | 南京邮电大学 | 一种基于对等网络的协议识别与控制系统的实现方法 |
CN103036803A (zh) * | 2012-12-21 | 2013-04-10 | 南京邮电大学 | 一种基于应用层检测的流量控制方法 |
-
2013
- 2013-06-28 CN CN201310262848.7A patent/CN103312565B/zh active Active
Patent Citations (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101599897A (zh) * | 2009-06-10 | 2009-12-09 | 南京邮电大学 | 一种基于应用层检测的对等网络流量控制方法 |
CN101741744A (zh) * | 2009-12-17 | 2010-06-16 | 东南大学 | 一种网络流量识别方法 |
CN101764754A (zh) * | 2009-12-28 | 2010-06-30 | 东南大学 | 基于dpi和dfi的业务识别系统中的样本获取方法 |
KR20120067528A (ko) * | 2010-12-16 | 2012-06-26 | 엘지에릭슨 주식회사 | 규칙 자기 학습 방법 및 그를 위한 lte 시스템 |
CN102185758A (zh) * | 2011-04-08 | 2011-09-14 | 南京邮电大学 | 一种基于阿瑞斯报文特征字的协议识别方法 |
CN102571946A (zh) * | 2011-12-28 | 2012-07-11 | 南京邮电大学 | 一种基于对等网络的协议识别与控制系统的实现方法 |
CN103036803A (zh) * | 2012-12-21 | 2013-04-10 | 南京邮电大学 | 一种基于应用层检测的流量控制方法 |
Non-Patent Citations (5)
Title |
---|
Design of P2P Traffic Identification based on DPI and DFI;chunzhi wang;《International Symposium on computer network and multimedia technology,CNMT 2009》;IEEE;20090120;第1-4页 * |
一种基于机器学习的P2P网络流量识别方法;李致远;《计算机研究与发现》;20111215;第48卷(第12期);第2253-2259页 * |
基于DPI和DFI技术的对等流量识别系统的设计;刘佳雄;《中国优秀硕士学位论文全文数据库(电子期刊)》;20100815;第20,31-45页 * |
基于Netfilter_Iptables内核扩展的P2P流量管理;徐苏磊;《计算机技术与发展》;20100630;第20卷(第6期);第101-105页 * |
基于特征值方法和机器学习方法P2P流量识别系统研究与设计;桑寅;《中国优秀硕士学位论文全文数据库(电子期刊)》;20120815;第14-26,39-51页 * |
Also Published As
Publication number | Publication date |
---|---|
CN103312565A (zh) | 2013-09-18 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN103312565B (zh) | 一种基于自主学习的对等网络流量识别方法 | |
CN106815112B (zh) | 一种基于深度包检测的海量数据监控系统及方法 | |
EP2944056B1 (en) | Distributed traffic inspection in a telecommunications network | |
CN102315974B (zh) | 基于层次化特征分析的tcp、udp流量在线识别方法和装置 | |
CN102045363B (zh) | 网络流量特征识别规则的建立方法、识别控制方法及装置 | |
CN102404396B (zh) | P2p流量识别方法、装置、设备和系统 | |
CN102739457B (zh) | 一种基于dpi和svm技术的网络流量识别方法 | |
US20120099597A1 (en) | Method and device for detecting a packet | |
CN104320304A (zh) | 一种易扩展的多方式融合的核心网用户流量应用识别方法 | |
CN106416171A (zh) | 一种特征信息分析方法及装置 | |
CN111224940B (zh) | 一种嵌套在加密隧道中的匿名服务流量关联识别方法及系统 | |
CN103873356B (zh) | 基于家庭网关的应用识别方法、系统和家庭网关 | |
US9894074B2 (en) | Method and system for extracting access control list | |
CN102571946B (zh) | 一种基于对等网络的协议识别与控制系统的实现方法 | |
CN101645803B (zh) | 点对点业务的识别方法和互联网业务识别系统 | |
CN106550241A (zh) | 视频业务识别系统及虚拟化部署方法 | |
US20140101751A1 (en) | Hardware engine for high-capacity packet processing of network based data loss prevention appliance | |
CN108206788B (zh) | 一种流量的业务识别方法及相关设备 | |
CN104243237A (zh) | P2p流检测方法和设备 | |
CN108833430B (zh) | 一种软件定义网络的拓扑保护方法 | |
CN102497297A (zh) | 基于多核多线程的深度报文检测技术的实现系统和方法 | |
CN106789728A (zh) | 一种基于NetFPGA的VoIP流量实时识别方法 | |
CN101753456B (zh) | 一种对等网络流量检测方法及其系统 | |
CN111224891B (zh) | 一种基于动态学习三元组的流量应用识别系统及方法 | |
CN105357129A (zh) | 一种基于软件定义网络的业务感知系统及方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20130918 Assignee: Jiangsu Nanyou IOT Technology Park Ltd. Assignor: NANJING University OF POSTS AND TELECOMMUNICATIONS Contract record no.: 2016320000214 Denomination of invention: Independent learning based peer-to-peer (P2P) network flow identification method Granted publication date: 20151223 License type: Common License Record date: 20161117 |
|
LICC | Enforcement, change and cancellation of record of contracts on the licence for exploitation of a patent or utility model | ||
EC01 | Cancellation of recordation of patent licensing contract | ||
EC01 | Cancellation of recordation of patent licensing contract |
Assignee: Jiangsu Nanyou IOT Technology Park Ltd. Assignor: NANJING University OF POSTS AND TELECOMMUNICATIONS Contract record no.: 2016320000214 Date of cancellation: 20180116 |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20191227 Address after: 224000 South 15 / F, intelligent Valley Science and technology building, Yannan high tech Zone, Yancheng City, Jiangsu Province Patentee after: NUPT INSTITUTE OF BIG DATA RESEARCH AT YANCHENG Address before: 210003, No. 66, new exemplary Road, Nanjing, Jiangsu Patentee before: NANJING University OF POSTS AND TELECOMMUNICATIONS |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20130918 Assignee: Yancheng Nongfu Technology Co.,Ltd. Assignor: NUPT INSTITUTE OF BIG DATA RESEARCH AT YANCHENG Contract record no.: X2023980048144 Denomination of invention: A peer-to-peer network traffic recognition method based on autonomous learning Granted publication date: 20151223 License type: Common License Record date: 20231127 |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20130918 Assignee: Jiangsu Yanan Information Technology Co.,Ltd. Assignor: NUPT INSTITUTE OF BIG DATA RESEARCH AT YANCHENG Contract record no.: X2023980049133 Denomination of invention: A peer-to-peer network traffic recognition method based on autonomous learning Granted publication date: 20151223 License type: Common License Record date: 20231203 Application publication date: 20130918 Assignee: Yanmi Technology (Yancheng) Co.,Ltd. Assignor: NUPT INSTITUTE OF BIG DATA RESEARCH AT YANCHENG Contract record no.: X2023980049119 Denomination of invention: A peer-to-peer network traffic recognition method based on autonomous learning Granted publication date: 20151223 License type: Common License Record date: 20231203 |