Method for recognizing and tracking application based on keyword sequence

A keyword sequence and application identification technology, applied in special data processing applications, instruments, electrical digital data processing, etc., can solve problems such as tracking of limited protocol status
CN101442535BInactive Publication Date: 2012-06-27SUN YAT SEN UNIV

Patent Information

Authority / Receiving Office
CN Β· China
Patent Type
Patents(China)
Current Assignee / Owner
SUN YAT SEN UNIV
Publication Date
2012-06-27
Estimated Expiration
Not applicable Β· inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides an application, identification and tracking method based on a keyword sequence, which comprises: firstly, establishing a keyword set; secondly, matching keywords with data in an application layer; thirdly, performing syntax tree judgment and evaluation on a keyword sequence obtained after matching; and fourthly, tracking the keyword sequence and identifying application types. The application, identification and tracking method based on the keyword sequence does not need manually understanding and programming an application layer protocol, manually analyzing unique characteristics of application and writing out a regular expression, can realize automatic modeling, identification and tracking of known or unknown application, and further realizes flow control and security defense of fine grain of the application and the application process.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of network security detection and network flow control, and in particular relates to an application identification and tracking method based on a keyword sequence. technical background

[0002] Existing methods for application layer protocol identification mainly include identification methods based on port numbers, methods based on manually established regular expressions, and methods based on statistical characteristics of flows. The method based on the protocol port number, because many standard applications use non-standard port numbers, and non-standard applications use standard port numbers, such as illegal applications and attacks that use well-known port numbers (such as port 80) to avoid firewall filtering and The limitation of traffic management equipment has made the method of identifying applications based on port numbers unsuitable. The regular expression-based application identification method...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More