摘要
针对蠕虫、DDOS攻击的大量存在严重地影响了网络的正常使用情况,使用基于Winpcap的流量监测技术,参照RTFM组织的流(Flow)定义方法,开发了一个简单实用的协议统计系统。系统采用校园网地址后12位作为哈希表的键值并建立一个专门统计传输层TCP、UDP端口以及网络层ICMP协议使用情况的数组。根据系统统计结果,网络管理者就可以判断校园网络是否处于正常运行状态,把网络管理者从传统的经验管理模式中解放出来,提高了网络管理与维护的效率。
The Worms and DDOS attacks have seriously affected the Intemet. So a simple and practical protocol statistical system was developed based on Winpcap traffic monitoring scheme and the RTFM' s definition of flow. The last 12 bits of campus network address was chosed as a hash table key and built a counter struct array on recording the TCP, UDP ports and ICMP usage. According to the statistical results, the network administrators can estimate if the campus network is in normal running state, which liberate the net- work administrators from traditional experienced mode of network management and improve the efficiency of network management.
出处
《鞍山科技大学学报》
2006年第3期259-262,共4页
Journal of Anshan University of Science and Technology