• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (4): 36-38.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • 上一篇    下一篇

基于多模匹配改进算法实现特征签名的动态协议探测技术

邓辉,梁波,王锋   

  1. (昆明理工大学云南省计算机技术应用重点实验室,云南 昆明 650051)
  • 收稿日期:2008-08-12 修回日期:2008-11-14 出版日期:2010-03-28 发布日期:2010-03-28
  • 通讯作者: 梁波 E-mail:lb@cnlab.net
  • 作者简介:邓辉(1972-),女,湖北恩施人,副教授, 研究方向为网络安全;梁波,硕士生;王锋,教授。

A Dynamic Protocol Detection Techniquefor the Signature Based on Optimizing the MultiPattern Matching Algorithms

DENG Hui,LIANG Bo,WANG Feng   

  1. (Yunnan Provincial Key Laboratory for Computer Technology Application,Kunming University of Science and Technology,Kunming 650051,China)
  • Received:2008-08-12 Revised:2008-11-14 Online:2010-03-28 Published:2010-03-28
  • Contact: LIANG Bo E-mail:lb@cnlab.net

摘要:

基于应用层协议的入侵检测依赖于特定的协议分析器从流中获取高层次的上下文,为了选择正确的分析器,传统的系统依赖于一些众所周知的端口号。正是因为这样的原理,很多非法的连接不使用标准端口或者采用隧道技术躲避入侵检测系统的检测。在本文中,我们希望实现一个利用包重组获得完整的数据流的上下文实现动态应用协议分析,以成功地检测到采用非常规手段的入侵。

关键词: 特征签名, 多模匹配, 动态协议分析, 报文重组, 入侵检测

Abstract: Many intrusion detection systems (IDS) rely on protocolspecific analyzers to extract the higherlevel semantic context from a traffic stream. In order to choose the right analyzer, the traditional systems rely on some wellknown ports.Thus, many illegal connections do not use the standard port or use the tunnel technology to evade the intrusion detection system’s testing. In this paper, we hope to achieve a complete reorganization of the data flow to achieve the context of dynamic application protocol analysis so as to detect the intrusion of using unconventional means.

Key words: signature;multipattern matching;dynamic protocol analysis;packet reorganization;intrusion detection

中图分类号: