长春理工大学学报(自然科学版)
長春理工大學學報(自然科學版)
장춘리공대학학보(자연과학판)
JOURNAL OF CHANGCHUN UNIVERSITY OF SCIENCE AND TECHNOLOGY(NATURAL SCIENCE EDITION)
2014年
5期
119-121,125
,共4页
王欢%赵建平%陈占芳%冯欣
王歡%趙建平%陳佔芳%馮訢
왕환%조건평%진점방%풍흔
多模式匹配%协议识别%活跃规则
多模式匹配%協議識彆%活躍規則
다모식필배%협의식별%활약규칙
multi-pattern matching%protocol identification%active rules
针对网络监听中应用层网络协议类型多、端口动态化、负载变化频繁、关键词匹配难度大等问题。本文提出了一种能够不降低被监听网络性能的多模式匹配的应用协议识别算法。首先根据模式串集合前后缀关系进行分类,然后采用正、反向匹配算法进行处理,最后采用活跃规则的方式对协议规则进行调度。实验结果表明,新算法在模式集较大的情况下,能明显提高应用协议识别的效率,并减少资源消耗,适用于实行大规模网络监听的生产环境。
針對網絡鑑聽中應用層網絡協議類型多、耑口動態化、負載變化頻繁、關鍵詞匹配難度大等問題。本文提齣瞭一種能夠不降低被鑑聽網絡性能的多模式匹配的應用協議識彆算法。首先根據模式串集閤前後綴關繫進行分類,然後採用正、反嚮匹配算法進行處理,最後採用活躍規則的方式對協議規則進行調度。實驗結果錶明,新算法在模式集較大的情況下,能明顯提高應用協議識彆的效率,併減少資源消耗,適用于實行大規模網絡鑑聽的生產環境。
침대망락감은중응용층망락협의류형다、단구동태화、부재변화빈번、관건사필배난도대등문제。본문제출료일충능구불강저피감은망락성능적다모식필배적응용협의식별산법。수선근거모식천집합전후철관계진행분류,연후채용정、반향필배산법진행처리,최후채용활약규칙적방식대협의규칙진행조도。실험결과표명,신산법재모식집교대적정황하,능명현제고응용협의식별적효솔,병감소자원소모,괄용우실행대규모망락감은적생산배경。
Aiming at the problem of the multiple types of application layer network protocol, port dynamic variety, load changing frequently, keyword matching difficultly in network monitoring, in this paper, an application protocol identification algorithm based on multi-pattern matching was presented, but the network performance could not be re-duced. Firstly, the set of pattern strings is classified with relation of prefix and suffix, and then processed by forward algorithm and reverse algorithm. The active rules is used for scheduling protocol rule. The experimental results show that with the larger the pattern set the efficiency of application protocol identification can be significantly improved by new algorithm and resource consumption can be reduced,the new algorithm are suitable for large-scale network moni-toring of the production environment.