信息网络安全 ›› 2016, Vol. 16 ›› Issue (2): 40-46.doi: 10.3969/j.issn.1671-1122.2016.02.007

• • 上一篇    下一篇

基于TcpFlow的网络可视分析系统研究与实现

孟浩1,2,3, 王劲松1,2,3(), 黄静耘1,2,3, 南慧荣1,2,3   

  1. 1. 天津理工大学计算机与通信工程学院,天津 300384
    2. 天津市智能计算及软件新技术重点实验室,天津 300384
    3. 计算机病毒防治技术国家工程实验室,天津 300457
  • 收稿日期:2015-12-14 出版日期:2016-02-10 发布日期:2020-05-13
  • 作者简介:

    作者简介: 孟浩(1989—),男,山东,硕士研究生,主要研究方向为网络安全与可视化;王劲松(1970—),男,天津,教授,博士,主要研究方向为信息安全、计算机网络;黄静耘(1992—),女,广东,硕士研究生,主要研究方向为网络安全与可视化;南慧荣(1992—),男,山西,硕士研究生,主要研究方向为网络安全。

  • 基金资助:
    国家自然科学基金[61272450];天津市科技支撑项目[14ZCZDGX00072]

Research and Implement on Network Visual Analytic System Based on TcpFlow

Hao MENG1,2,3, Jinsong WANG1,2,3(), Jingyun HUANG1,2,3, Huirong NAN1,2,3   

  1. 1. School of Computer and Communication Engineering, Tianjin University of Technology, Tianjin 300384, China
    2. Tianjin Key Laboratory of Intelligence Computing and Novel Software Technology, Tianjin 300384, China
    3. National Engineering Laboratory for Computer Virus Prevention and Control Technology, Tianjin 300457,China
  • Received:2015-12-14 Online:2016-02-10 Published:2020-05-13

摘要:

文章设计了一款对TcpFlow数据进行网络分析的可视分析系统,其主要功能是区分网络中的服务器与客户端、划分网络拓扑结构、对服务器进行分类,发现网络中存在的通信模式。该系统主要分为两个模块,第一个模块通过对网络主机TcpFlow数据流量信息的可视分析,对网络结构和主机进行分析;第二个模块通过对时序的TcpFlow数据进行会话通信过程的可视化展现,能够发现网络通信中特殊的通信模式,能够实时在线对网络通信模式进行分析和研究。该系统可以帮助网络管理人员及网络安全分析人员快速了解整个网络结构和网络运行特征,便于对网络的管理以及对网络安全事态的感知。

关键词: 网络结构分析, 网络通信模式, TcpFlow, 可视分析

Abstract:

This paper designs a visual analytic system for analyzing the structure of network by using TcpFlow data. Its functions include distinguishing the hosts between clients and servers in the network, dividing the topology of network, classing the servers, and finding communication modes. The system has two modules. The first module is used to analyze the structure and hosts of the network by visual analysis of the TcpFlow data. And we can also use it to discover special communication modes through visualizing the session procedures of the TcpFlow data. Meanwhile, the second module can be used to analyze the network communication modules real-timely. With these two modules, the system can help network administrators and network security analysts understand the structure of the whole network and characteristics of the network quickly, and make it convenient to the management of the network and perception of network security situation.

Key words: analysis of network structure, network communication mode, TcpFlow, visual analysis

中图分类号: