Unknown protocol message format deduction method
Patent Information
- Authority / Receiving Office
- CN Β· China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SOUTHWEST CHINA RES INST OF ELECTRONICS EQUIP
- Publication Date
- 2015-09-23
Smart Images
Figure 1 Figure 2 Figure 3
Abstract
Description
technical field
[0001] The invention belongs to the field of network data flow unknown protocol identification, and specifically relates to an unknown protocol message format inference method, which utilizes data packets intercepted in the network and uses data packet sequence comparison technology to realize the unknown protocol data message format inference. Background technique
[0002] The current protocol identification technology mainly includes protocol identification technology based on port mapping, deep packet inspection protocol identification technology based on static features, and protocol identification technology based on dynamic behavior features. These methods are all based on extracting the protocol features of this type of protocol from the public protocol specification, and then building the feature library of the protocol as the basis for identification.
[0003] According to the protocol format specification, the traffic can be identified by the applic...