• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

A protocol classification algorithm based on improved AGNES

ZHANG Feng-li1,ZHOU Hong-chuan1,ZHANG Jun-jiao1,LIU Yuan2,ZHANG Chun-rui2   

  1. (1.School of Information and Software Engineering,University of Electronic Science & Technology of China,Chengdu 611731;
    2.Institute of Computer Application,China Academy of Engineering Physics,Mianyang 621900,China)
     
  • Received:2015-06-22 Revised:2016-01-29 Online:2017-04-25 Published:2017-04-25

Abstract:

In the process of bit-stream unknown protocol identification, how to separate multi-protocol data frames into single protocol data frames is a challenging issue. To solve this problem, we propose an improved algorithm based on the idea of traditional AGNES algorithm. Combining the features of bit-stream data frames, this algorithm can define the similarity between data frames and the similarity between clusters by two different ways. We perform clustering and extract clusters that meet the requirements of the class cluster simultaneously. Protocol data frames can be clustered quickly and effectively without inputting the number of clusters. And a similarity evaluation is included in the results of class clusters. Tests on the data set published by the Lincoln Laboratory show that the algorithm has a higher accuracy rate for clustering protocol data frames.

Key words: unknown protocol, protocol identification, hierarchical clustering algorithm, clustering