摘要
针对当前P2P流量消耗大量带宽,降低接入网络性能的问题,采用规则匹配的方法,借助入侵检测系统Snort的链表结构,设计了一种局域网P2P流量识别系统,该系统综合使用端口识别和特征匹配两种传统方法进行检测,并采用一种动态规则匹配机制,增加选项索引链表,对规则匹配的次序进行动态调整,从而提高规则匹配的速度。实验结果表明该系统可迅速发现并准确提示不同P2P流量。
Aiming at the high bandwidth assumption of P2P (peer to peer) flow, a LAN P2P flow identification system is designed based on Rule-matching and chain structure of IDS Snort. Two main traditional methods, port identification and feature matching are synthetically used in this system. In order to increase the rule- matching speed effectively, a dynamic mechanism is applied. By a chain of the option index, the sequence of rule-matching is adjusted dynamically. The experimental results indicate that this system can rapidly discover and further accurately alarm the different P2P flow.
出处
《电子设计工程》
2011年第20期58-60,67,共4页
Electronic Design Engineering
基金
国家自然科学基金(61040005)
中国博士后科学基金面上资助项目(20110491638)
陕西省自然科学基金(2011JQ8036)
关键词
流量识别
P2P
SNORT
链表结构
规则
flow identification
peer to peer (P2P)
Snort
chain structure
rule