信息网络安全 ›› 2020, Vol. 20 ›› Issue (1): 16-25.doi: 10.3969/j.issn.1671-1122.2020.01.003

• 技术研究 • 上一篇    下一篇

面向属性迁移状态的P2P网络行为分析方法研究

荆涛1(), 万巍2   

  1. 1. 中国科学院办公厅,北京 100864
    2. 中国科学院计算机网络信息中心,北京 100190
  • 收稿日期:2019-10-15 出版日期:2020-01-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:荆涛(1979—),男,吉林,高级工程师,博士,主要研究方向为网络与信息安全、流量协议分析;万巍(1982—),男,湖北,高级工程师,博士,主要研究方向为网络空间安全。

  • 基金资助:
    中国科学院信息化专项[XXH13507]

Research on a P2P Network Communication Behavior Analytical Method for Status Migration Attribute-oriented

JING Tao1(), WAN Wei2   

  1. 1. Office of General Affairs, Chinese Academy of Sciences, Beijing 100864, China
    2. Computer Network Information Center of the Chinese Academy of Sciences, Beijing 100190, China
  • Received:2019-10-15 Online:2020-01-10 Published:2020-05-11

摘要:

文章针对网络中网络带宽占用较大,通信较为频繁的网络行为的通信属性状态的变化特点,提出了面向属性迁移状态的网络通信行为分析方法。通过对各类行为中分阶段迁移状态的属性参数的讨论,给出了不同阶段属性和端口的相应迁移状态特性,研究并提出了P2P行为识别方法。通过实验,验证了该方法对P2P应用的识别效果和可靠性。

关键词: 网络安全, 行为识别, 异常行为检测, 属性分析

Abstract:

For the network property status changes characteristic behaviors of which had greater network bandwidth and more frequent communication, we proposed a network communication behavior analytical method for status migration attribute-oriented. According to the discussing by phased migration status for attribute parameter, we gave the corresponding attributes and characteristics of the different stages for port. And then, we researched the behavior of P2P recognition model. Through the experiments we validated performance and reliability of this method for identifying P2P application.

Key words: network security, behavior identification, anomaly behavior detection, attribute analysis

中图分类号: