CN108924010A - 一种通信协议识别方法及装置 - Google Patents
一种通信协议识别方法及装置 Download PDFInfo
- Publication number
- CN108924010A CN108924010A CN201810827599.4A CN201810827599A CN108924010A CN 108924010 A CN108924010 A CN 108924010A CN 201810827599 A CN201810827599 A CN 201810827599A CN 108924010 A CN108924010 A CN 108924010A
- Authority
- CN
- China
- Prior art keywords
- bit
- sequence
- bit stream
- frequent mode
- mode
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000004891 communication Methods 0.000 title claims abstract description 57
- 238000000034 method Methods 0.000 title claims abstract description 40
- 238000012216 screening Methods 0.000 claims description 10
- 238000004590 computer program Methods 0.000 claims description 6
- 230000001737 promoting effect Effects 0.000 abstract description 5
- 238000005516 engineering process Methods 0.000 description 9
- 238000010586 diagram Methods 0.000 description 8
- 238000012360 testing method Methods 0.000 description 7
- 238000012545 processing Methods 0.000 description 6
- 238000004458 analytical method Methods 0.000 description 5
- 230000008569 process Effects 0.000 description 4
- 230000005540 biological transmission Effects 0.000 description 3
- 238000010168 coupling process Methods 0.000 description 3
- 238000005859 coupling reaction Methods 0.000 description 3
- 238000012217 deletion Methods 0.000 description 3
- 230000037430 deletion Effects 0.000 description 3
- 238000001514 detection method Methods 0.000 description 3
- 238000013179 statistical model Methods 0.000 description 3
- 238000004364 calculation method Methods 0.000 description 2
- 230000008878 coupling Effects 0.000 description 2
- 230000006870 function Effects 0.000 description 2
- 238000013178 mathematical model Methods 0.000 description 2
- 238000013138 pruning Methods 0.000 description 2
- 238000003491 array Methods 0.000 description 1
- 238000009412 basement excavation Methods 0.000 description 1
- 238000007405 data analysis Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 230000008450 motivation Effects 0.000 description 1
- 238000005192 partition Methods 0.000 description 1
- 238000000926 separation method Methods 0.000 description 1
- 238000002864 sequence alignment Methods 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/22—Parsing or analysis of headers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/18—Protocol analysers
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Communication Control (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810827599.4A CN108924010A (zh) | 2018-07-25 | 2018-07-25 | 一种通信协议识别方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810827599.4A CN108924010A (zh) | 2018-07-25 | 2018-07-25 | 一种通信协议识别方法及装置 |
Publications (1)
Publication Number | Publication Date |
---|---|
CN108924010A true CN108924010A (zh) | 2018-11-30 |
Family
ID=64416862
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810827599.4A Pending CN108924010A (zh) | 2018-07-25 | 2018-07-25 | 一种通信协议识别方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108924010A (zh) |
Cited By (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110336817A (zh) * | 2019-07-08 | 2019-10-15 | 大连大学 | 一种基于TextRank的未知协议帧定位方法 |
CN110697522A (zh) * | 2019-09-19 | 2020-01-17 | 广州慧特安科技有限公司 | 电梯通信协议的检测方法、系统和存储介质 |
CN111049852A (zh) * | 2019-12-24 | 2020-04-21 | 国家计算机网络与信息安全管理中心 | Can总线协议解析方法、装置、电子设备及存储介质 |
CN112104518A (zh) * | 2019-08-26 | 2020-12-18 | 中国科学院国家空间科学中心 | 一种比特数据特征挖掘方法、系统、设备及可读介质 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8949592B2 (en) * | 2011-03-23 | 2015-02-03 | Google Technology Holdings | System and methods for providing live streaming content using digital rights management-based key management |
CN105791278A (zh) * | 2016-02-29 | 2016-07-20 | 中国工程物理研究院计算机应用研究所 | 一种未知二进制协议帧切分与层次划分方法 |
CN107689899A (zh) * | 2017-09-01 | 2018-02-13 | 南京南瑞集团公司 | 一种基于比特流的未知协议识别方法及系统 |
-
2018
- 2018-07-25 CN CN201810827599.4A patent/CN108924010A/zh active Pending
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8949592B2 (en) * | 2011-03-23 | 2015-02-03 | Google Technology Holdings | System and methods for providing live streaming content using digital rights management-based key management |
CN105791278A (zh) * | 2016-02-29 | 2016-07-20 | 中国工程物理研究院计算机应用研究所 | 一种未知二进制协议帧切分与层次划分方法 |
CN107689899A (zh) * | 2017-09-01 | 2018-02-13 | 南京南瑞集团公司 | 一种基于比特流的未知协议识别方法及系统 |
Non-Patent Citations (1)
Title |
---|
王和洲等: "基于频繁统计和关联规则的未知链路协议比特流切割算法", 《中国科学技术大学学报》 * |
Cited By (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110336817A (zh) * | 2019-07-08 | 2019-10-15 | 大连大学 | 一种基于TextRank的未知协议帧定位方法 |
CN110336817B (zh) * | 2019-07-08 | 2021-08-10 | 大连大学 | 一种基于TextRank的未知协议帧定位方法 |
CN112104518A (zh) * | 2019-08-26 | 2020-12-18 | 中国科学院国家空间科学中心 | 一种比特数据特征挖掘方法、系统、设备及可读介质 |
CN112104518B (zh) * | 2019-08-26 | 2021-06-08 | 中国科学院国家空间科学中心 | 一种比特数据特征挖掘方法、系统、设备及可读介质 |
CN110697522A (zh) * | 2019-09-19 | 2020-01-17 | 广州慧特安科技有限公司 | 电梯通信协议的检测方法、系统和存储介质 |
CN110697522B (zh) * | 2019-09-19 | 2022-03-25 | 广州慧特安科技有限公司 | 电梯通信协议的检测方法、系统和存储介质 |
CN111049852A (zh) * | 2019-12-24 | 2020-04-21 | 国家计算机网络与信息安全管理中心 | Can总线协议解析方法、装置、电子设备及存储介质 |
CN111049852B (zh) * | 2019-12-24 | 2020-12-08 | 国家计算机网络与信息安全管理中心 | Can总线协议解析方法、装置、电子设备及存储介质 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108924010A (zh) | 一种通信协议识别方法及装置 | |
CN108234524B (zh) | 网络数据异常检测的方法、装置、设备及存储介质 | |
CN110519290B (zh) | 异常流量检测方法、装置及电子设备 | |
EP3343869B1 (en) | A method for modeling attack patterns in honeypots | |
CN108011925B (zh) | 一种业务审计系统及方法 | |
US10182011B2 (en) | System and method to analyze congestion in low latency network | |
US20200021511A1 (en) | Performance analysis for transport networks using frequent log sequence discovery | |
CN111294233A (zh) | 网络告警统计分析方法、系统及计算机可读存储介质 | |
CN106878038B (zh) | 一种通信网络中故障定位方法及装置 | |
CN112751711B (zh) | 告警信息处理方法和装置、存储介质和电子设备 | |
CN111371651A (zh) | 一种工业通讯协议逆向分析方法 | |
US8756312B2 (en) | Multi-tier message correlation | |
CN110717551B (zh) | 流量识别模型的训练方法、装置及电子设备 | |
CN112468365A (zh) | 用于网络镜像流量的数据质量检测方法、系统及介质 | |
US8782092B2 (en) | Method and apparatus for streaming netflow data analysis | |
CN117807589B (zh) | 一种基于工业控制系统入侵检测的关联分析方法 | |
CN106649344B (zh) | 一种网络日志压缩方法和装置 | |
CN113987492A (zh) | 一种告警事件的确定方法及装置 | |
CN109981389A (zh) | 手机号码识别方法、装置、设备及介质 | |
Li et al. | A lightweight intrusion detection model based on feature selection and maximum entropy model | |
CN108399266B (zh) | 数据抽取方法、装置、电子设备及计算机可读存储介质 | |
CN105446284B (zh) | Can总线的数据分析方法和装置 | |
CN107330031B (zh) | 一种数据存储的方法、装置及电子设备 | |
CN108243058A (zh) | 一种基于告警定位故障的方法和装置 | |
CN104753934A (zh) | 将未知协议多通信方数据流分离为点对点数据流的方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20191009 Address after: 100031 Xicheng District West Chang'an Avenue, No. 86, Beijing Applicant after: State Grid Co., Ltd. Applicant after: NARI Group Co. Ltd. Applicant after: Beijing Kedong Power Control System Co., Ltd. Applicant after: State Grid Hebei Electric Power Co., Ltd. Applicant after: INFORMATION COMMUNICATION COMPANY, STATE GRID GANSU ELECTRIC POWER CO., LTD. Address before: 100192 Beijing city Haidian District Qinghe small Camp Road No. 15 Applicant before: Beijing Kedong Power Control System Co., Ltd. Applicant before: State Grid Hebei Electric Power Co., Ltd. Applicant before: INFORMATION COMMUNICATION COMPANY, STATE GRID GANSU ELECTRIC POWER CO., LTD. |
|
TA01 | Transfer of patent application right | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20181130 |
|
RJ01 | Rejection of invention patent application after publication |