Unlock instant, AI-driven research and patent intelligence for your innovation.

HTTP data characteristic analysis method and system

A technology of data characteristics and analysis methods, applied in the direction of digital transmission systems, transmission systems, data exchange networks, etc., can solve the problems of not caring about upper-layer applications, decline in recognition ability, and wide use, so as to reduce strong consumption and high dependence, The effect of optimizing the recognition process and improving the recognition ability

Active Publication Date: 2017-02-22
苏州迈科网络安全技术股份有限公司
View PDF7 Cites 7 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] However, due to the constraints of hardware performance, function adaptation, system architecture and other factors, DPI has not been widely used in a large number of low-end network devices (such as home routers, commercial WIFI, thin APs, etc.), mainly due to traditional DPI technology. When performing data analysis, most do not care about the specific data structure of the upper-layer application. The source data is scanned byte by byte from the head of the data until the end of the data or the specified number of bytes, and then judge whether it is consistent with the data from the scanned data. Match the fingerprint library to obtain the identification of the source data
[0004] Starting from the first byte of data to scan, the whole process has high requirements on system resources, so DPI technology can only be applied to large-scale network devices with abundant resources, but cannot be used for small network devices such as home gateways and commercial WiFi, resulting in The lack of advanced traffic optimization and service improvement for the majority of end users, so it is necessary to implement deep packet inspection technology that can be adapted to low-end network equipment
[0005] In addition, since more than 80% of the current Internet data, especially mobile Internet data, is application data based on the HTTP protocol, the in-depth analysis of the HTTP protocol will greatly affect the performance consumption and recognition ability of DPI
[0006] In order to achieve both performance, it is often impossible to achieve full data coverage during data scanning, especially the problem that HTTP protocol data cannot be fully covered, so the risk of feature misjudgment and missed judgment will increase, making application identification Decrease in ability

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0031] The HTTP data feature analysis method disclosed by the present invention is characterized in that: comprising the following steps:

[0032] S1, receiving the injected Internet data, and judging whether the injected Internet data is HTTP data;

[0033] As a common application layer data, HTTP data flow has obvious characteristics. HTTP data is transmitted by TCP flow with destination port 80. At the same time, according to the relevant regulations of HTTP RFC, its data flow is divided into request and response. HTTP request data The structure is divided into Head Domain and Body Domain, where Head Domain contains information such as HTTP request method, request URI, request domain name, etc. Therefore, we analyze the data packets of the monitored TCP data flow, and judge its port, data structure and Determine whether it is HTTP data.

[0034] The specific judgment process is as follows: judge whether the received data stream is TCP data, if so, check whether the destina...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses an HTTP data characteristic analysis method and system. The method comprises: S1, judging whether injected internet data is HTTP data or not; S2, when the injected internet data is not judged as the HTTP data, enabling the internet data to go into a DPI (Deep Packet Inspection) engine to run a deep packet characteristic inspection; S3, when the injected internet data is judged as the HTTP data, identifying a body domain and a head of the HTTP data; S4, enabling the body domain to directly go into the DPI engine to run the deep packet characteristic inspection without subsection analysis; and S5, enabling the head to go into an HTTP_DPI engine to run analysis, wherein the HTTP_DPI engine divides the head into a plurality of pointer structures, performs independent parallel analysis according to the pointer structures, and marks the data matched with a characteristic fingerprint database as an application showed by a characteristic fingerprint after the characteristic fingerprint database is matched. According to the HTTP data characteristic analysis method and system, large consumption and high dependency of the system resource are effectively decreased; meanwhile all the data is effectively covered, especially the HTTP data, the risk of the characteristic false positives and false negatives is decreased, and the identification ability of the application is improved.

Description

technical field [0001] The invention relates to a data feature analysis method and system, in particular to an HTTP data feature analysis method and system. Background technique [0002] Deep Packet Inspection (Deep Packet Inspection, hereinafter referred to as DPI) is a traffic analysis and detection technology oriented to application layer analysis. DPI technology has become the standard configuration of high-end network equipment, and is used for fine-grained control and monitoring of network traffic. analyze. [0003] However, due to the constraints of hardware performance, function adaptation, system architecture and other factors, DPI has not been widely used in a large number of low-end network devices (such as home routers, commercial WIFI, thin APs, etc.), mainly due to traditional DPI technology. When performing data analysis, most do not care about the specific data structure of the upper-layer application. The source data is scanned byte by byte from the head of...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L12/26H04L29/06H04L29/08
Inventor 丁增红周明中
Owner 苏州迈科网络安全技术股份有限公司