...
首页> 外文期刊>Enterprise information systems >A feasibility study of stateful automaton packet inspection for streaming application detection systems
【24h】

A feasibility study of stateful automaton packet inspection for streaming application detection systems

机译:流应用检测系统有状态自动机数据包检测的可行性研究

获取原文
获取原文并翻译 | 示例
           

摘要

The rapid development of the internet has brought huge benefits and social impacts; however, internet security has also become a great problem for users, since traditional approaches to packet classification cannot achieve satisfactory detection performance due to their low accuracy and efficiency. In this paper, a new stateful packet inspection method is introduced, which can be embedded in the network gateway and used by a streaming application detection system. This new detection method leverages the inexact automaton approach, using part of the header field and part of the application layer data of a packet. Based on this approach, an advanced detection system is proposed for streaming applications. The workflow of the system involves two stages: the training stage and the detection stage. In the training stage, the system initially captures characteristic patterns from a set of application packet flows. After this training is completed, the detection stage allows the user to detect the target application by capturing new application flows. This new detection approach is also evaluated using experimental analysis; the results of this analysis show that this new approach not only simplifies the management of the state detection system, but also improves the accuracy of data flow detection, making it feasible for real-world network applications.
机译:互联网的飞速发展带来了巨大的利益和社会影响。然而,由于传统的分组分类方法由于其低准确性和高效率而无法获得令人满意的检测性能,因此互联网安全对于用户来说也已成为一个大问题。本文介绍了一种新的有状态包检查方法,该方法可以嵌入网络网关中,并由流应用程序检测系统使用。这种新的检测方法利用了报头字段的一部分和数据包的部分应用程序层数据,利用了不精确的自动机方法。基于这种方法,提出了一种针对流应用的高级检测系统。系统的工作流程包括两个阶段:训练阶段和检测阶段。在训练阶段,系统最初从一组应用程序包流中捕获特征模式。在完成此训练之后,检测阶段允许用户通过捕获新的应用程序流来检测目标应用程序。还使用实验分析来评估这种新的检测方法。分析结果表明,这种新方法不仅简化了状态检测系统的管理,而且提高了数据流检测的准确性,使其在实际的网络应用中可行。

著录项

  • 来源
    《Enterprise information systems》 |2017年第10期|1317-1336|共20页
  • 作者单位

    Harbin Inst Technol, Shenzhen Grad Sch, Dept Comp Sci & Technol, Shenzhen, Peoples R China;

    Harbin Inst Technol, Shenzhen Grad Sch, Dept Comp Sci & Technol, Shenzhen, Peoples R China;

    Harbin Inst Technol, Shenzhen Grad Sch, Dept Comp Sci & Technol, Shenzhen, Peoples R China;

    Tamkang Univ, Dept Comp Sci & Informat Engn, New Taipei, Taiwan;

    Liverpool John Moores Univ, Sch Comp & Math Sci, Liverpool, Merseyside, England;

    Hong Kong Polytech Univ, Dept Ind & Syst Engn, Hong Kong, Hong Kong, Peoples R China;

    Hong Kong Polytech Univ, Dept Ind & Syst Engn, Hong Kong, Hong Kong, Peoples R China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Firewall; packet classification; stateful automaton; Aho-Corasick;

    机译:防火墙;数据包分类;状态自动机;Aho-Corasick;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号