信息网络安全 ›› 2016, Vol. 16 ›› Issue (10): 69-75.doi: 10.3969/j.issn.1671-1122.2016.10.011

• • 上一篇    下一篇

基于缓存命中的DPI系统预处理方法

马跃鹏(), 刘吉强, 王健   

  1. 北京交通大学计算机与信息技术学院,北京100044
  • 收稿日期:2016-09-01 出版日期:2016-10-31 发布日期:2020-05-13
  • 作者简介:

    作者简介: 马跃鹏(1991—),男,河北,硕士研究生,主要研究方向为计算机安全;刘吉强(1973—),男,山东,教授,博士,主要研究方向为可信计算、安全协议;王健(1975—),男,山东,讲师,博士,主要研究方向为网络信息安全。

  • 基金资助:
    国家自然科学基金[61672092]

A Pretreatment of DPI System Based on the Cache Hit

Yuepeng MA(), Jiqiang LIU, Jian WANG   

  1. School of Computer and Information Technology of Beijing Jiaotong University, Beijing 100044, China
  • Received:2016-09-01 Online:2016-10-31 Published:2020-05-13

摘要:

移动网络数据业务的迅猛增长在带来便利和收益的同时,也产生了诸多的安全隐患,为了净化移动网络环境,挖掘网络数据的潜在价值,运营商多采用移动数据流量DPI系统来统一监管网络数据, 但面对高速网络数据,DPI的处理性能堪忧。为了优化高速网络数据下的DPI处理效率,文章提出一种基于缓存命中的预处理方法。以数据包的五元组信息作为键,以封装有协议特征标记的连接作为值,创建哈希结构缓存,后续到来的数据包在进入DPI处理前,检索缓存区相应键值对,若命中则将其标记成已识别数据包,这样就避免了部分的数据包进行DPI的模式匹配处理,减小了DPI处理压力,提高了系统的吞吐量。实验证明该方法可有效提升移动网络数据解析效率。

关键词: 移动网络数据, DPI, 缓存命中, 五元组, 协议特征标记

Abstract:

The rapid growth of data services in mobile network brings not only convenience and benefits,but also lots of security risks.In order to purify the mobile network environment and mining the potential value of network data,more and more operators use DPI(Deep Packet Inspection) systems on mobile data traffic to supervise the network data.However,facing high speed network data,DPI systems have a poor performance.In order to improve the efficiency of DPI processing in high speed network data,this paper proposes a new method of pretreatment based on the cache hit.The five-tuple of the data packets used as the key and the connection with the protocol mark used as the value,create the hash structure cache.Before arrival packets entering the DPI process,search their key-value pairs in the cache.If the key-value pair is found,mark the packet identified.By avoiding pattern matching processing of some data packets,the DPI processing pressure is reduced,and the throughput of the system if improved.Experiments show that this method effectively enhance the efficiency of the analysis of mobile network data.The method is feasible and can be recommended.

Key words: mobile network data, DPI, cache hit, five-tuple, protocol mark

中图分类号: