期刊文献+

基于正则表达式的动态应用层协议识别方案 被引量:8

Dynamic application layer protocol identification program based on regular expressions
下载PDF
导出
摘要 传统依赖于端口号的应用层协议识别方法对大量具有随机端口的应用不再适用,设计一种基于正则表达式的动态应用层协议识别方案。在深入分析DFA状态数对算法性能影响的基础上,提出了构造最优DFA状态数的算法,该算法保证在任意有限的系统资源下具有最小的时间复杂度和空间复杂度,并且将报文匹配方式和One-Pass扫描算法相结合进行测试。实验表明此方案具有较低的资源消耗率,较高识别效率和识别精度。 Traditional methods of application-layer protocol identification such as using default server port are no longer applica-ble to a large number of random ports application.A dynamic application-layer protocol identification based on regular expression is designed.Through analyzing the impact of number of DFA states to the algorithm performance,a DFA state number optimization algorithm is proposed.This algorithm has the little time complexity and space complexity under the limited system resource.And then packet matching patterns are tested with One-Pass scanning algorithm.Experimental results show that this program has a lower rate of resource consumption,higher efficiency of the identification and recognition accuracy.
作者 王杰 石成辉
出处 《计算机工程与应用》 CSCD 北大核心 2010年第18期103-106,共4页 Computer Engineering and Applications
基金 河南省杰出人才创新基金(No.074200510013) 河南省教育厅自然科学基金(No.2007520048)
关键词 协议识别 正则表达式 最优DFA状态数 One-Pass扫描算法 protocol identification regular expression DFA state number optimization One-Pass scanning algorithm
  • 相关文献

参考文献9

  • 1Network ICE.Protocol analysis and command parsing vs.pattern matching in intrusion detection systems[EB/OL].http://oldhand.org/document/ ids/Protocol_Analysis_VS_Pattern.pdf. 被引量:1
  • 2周华先,王伟平.基于Linux下L7-filter模块的P2P流量控制[J].湖南科技学院学报,2008,29(4):127-129. 被引量:3
  • 3Dreger H,Feldmann A,Mai M,et al.Dynamic application-layer protocol analysis for network intrusion detection[C]//15th USENIX Security Symposium, 2006,15 : 257-272. 被引量:1
  • 4Aho A V,.Sethi R,Ullman J D.Compilers:Principles,techniques,and tools[M].[S.l.] : Addison-Wesley, 1986. 被引量:1
  • 5正则表达式参考文档[EB/OL].http;//www.regexlab.com/zh/regref.htm. 被引量:2
  • 6邓超成.正规文法、NFA、DFA、状态转换图、正规式之间的等价变换关系及变换方法[J].四川师范大学学报(自然科学版),1997,20(2):89-92. 被引量:2
  • 7Tremblay J P,Sorenson P G.The theory and practice of compiler writing[M].[S.l.] : McGraw-Hill, 1985. 被引量:1
  • 8Thompson K.Regular expression search algorithm[J].Communieations of the ACM, 1986,11:419-422. 被引量:1
  • 9Sohau H,Metza F,Fugen C,et al.A one-pass decoder based on polymorphic linguistic context assigument[C]//Proceedings of the Automatic Speech and Recognition Workshop(ASRU), Madonna di Campiglio Trento,haly,2001. 被引量:1

二级参考文献3

共引文献4

同被引文献79

引证文献8

二级引证文献25

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部