Supercharge Your Innovation With Domain-Expert AI Agents!

Method for analyzing non-public database protocol request data packet

A technology for requesting data packets and parsing methods, applied in the field of network security communication, can solve problems such as incomplete coverage of strings, undisclosed communication protocols, slow parsing speed, etc., to facilitate auditing and monitoring, comprehensive audit scope, and save memory. occupied effect

Active Publication Date: 2019-12-17
ZHENGZHOU SEANET TECH CO LTD
View PDF5 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] The purpose of the present invention is to overcome the existing character strings in the current method for directional matching of specific character strings that cannot fully cover all the content in this type of non-public database, and cannot match and parse some wrong commands or meaningless character strings. Unstable performance and slow parsing speed. Provides a non-public database protocol request packet parsing method, solves the problem of difficult audit and monitoring caused by non-public database communication protocols, and improves the safety factor.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for analyzing non-public database protocol request data packet
  • Method for analyzing non-public database protocol request data packet
  • Method for analyzing non-public database protocol request data packet

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0047] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0048] like figure 1 As shown, the method for parsing the non-public database protocol request data packet of the present invention, the method can parse the request content contained in the non-public database protocol request data packet, and the method includes:

[0049] Step 1) extract several request rules, the request rules include: the starting position of the non-public database protocol request data packet header, the occurrence position of the request command length field and the request command start position, and each request rule and its The unchangeable field data in the request rule forms the protocol message rule table;

[0050] Step 2) according to the protocol message rule table obtained in step 1), mark the invariable field in each request rule as a coloring node, and generate a rule tree;

[0051] Step 3) find the rule tre...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses an analysis method of a non-public database protocol request data packet. The method comprises the following steps: step 1) extracting a plurality of request rules, including an initial position of a request data packet message header, an occurrence position of a request command length field and a request command initial position, and forming a protocol message rule table by using each request rule and data of a field determined to be unchanged in each request rule; 2) according to the protocol message rule table obtained in the step 1), marking a field determined to beunchanged in each request rule as a coloring node, and generating a rule tree; 3) searching the rule tree generated in the step 2), inputting the message of the request data packet to be analyzed andthe rule tree corresponding to the message, and matching each data packet to be analyzed with the rule tree to obtain a request rule corresponding to the rule leaf node; and 4) analyzing the to-be-analyzed data packet according to the initial position of the message header in the request rule, the appearing position of the request command length field and the starting position of the request command, and obtaining the request command.

Description

technical field [0001] The invention relates to the field of network security communication, in particular to a non-public database protocol request data packet analysis method. Background technique [0002] Computer network security audit (Audit) refers to the use of records, system activities and user activities and other information to check, review and verify the environment and activities of operational events in accordance with certain security policies, so as to discover system vulnerabilities, intrusion behaviors or improve system performance. process. [0003] However, when auditing some database traffic, the communication protocol standards of some databases are not disclosed, which leads to difficulties in security auditing and real-time monitoring of such databases, and there are security risks when using them. At present, the more commonly used method is the method of directional matching of specific strings. Parsing, unstable performance, slow parsing. SUMM...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): H04L29/06
CPCH04L69/03H04L69/22
Inventor 宋磊吉祥张润滋刘磊
Owner ZHENGZHOU SEANET TECH CO LTD
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More