【24h】

Probabilistic Identification for Hard to ClassifyProtocol

机译:难以识别的概率识别协议

获取原文
获取原文并翻译 | 示例

摘要

With the growing use of protocols obfuscation techniques, protocol identification for Q.O.S enforcement, traffic prohibition, and intrusion detection has became a complex task. This paper address this issue with a probabilistic identification analysis that combines multiples advanced identification techniques and returns an ordered list of probable protocols. It combines a payload analysis with a classifier based on several discriminators, including packet entropy and size. We show with its implementation, that it overcomes the limitations of traditional port-based protocol identification when dealing with hard to classify protocol such as peer to peer protocols. We also details how it deals with tunneled session and covert channel.
机译:随着协议混淆技术的广泛使用,用于Q.O.S实施,流量禁止和入侵检测的协议识别已成为一项复杂的任务。本文通过概率识别分析解决了这个问题,该分析结合了多种高级识别技术并返回了可能的协议的有序列表。它结合了有效载荷分析和基于多个鉴别器的分类器,包括分组熵和大小。我们以其实现方式展示,它在处理难以分类的协议(例如对等协议)时克服了传统的基于端口的协议标识的局限性。我们还将详细介绍它如何处理隧道会话和隐蔽通道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号