论文部分内容阅读
现有基于网络报文流量信息的协议分析方法仅考虑报文载荷中的明文信息,不适用于包含大量密文信息的安全协议。为充分发掘利用未知规范安全协议的密文数据特征,针对安全协议报文明密文混合、密文位置可变的特点,该文提出一种基于熵估计的安全协议密文域识别方法 CFIA(Ciphertext Field Identification Approach)。在挖掘关键词序列的基础上,利用字节样本熵描述网络流中字节的分布特性,并依据密文的随机性特征,基于熵估计预定位密文域分布区间,进而查找密文长度域,定位密文域边界,识别密文域。实验结果表明,该方法仅依靠网络数据流量信息即可有效识别协议密文域,并具有较高的准确率。
The existing protocol analysis method based on network packet traffic information only considers the plaintext information in the packet payload and does not apply to the security protocol which contains a large amount of ciphertext information. In order to fully exploit the characteristics of ciphertext data using unknown protocols, this paper proposes a security protocol ciphertext recognition method based on entropy estimation CFIA (Ciphertext Field Identification Approach). Based on the mining of keyword sequences, the byte-sample entropy is used to describe the distribution characteristics of bytes in network flows. Based on the random character of ciphertexts, the distribution of pre-positioned ciphertext regions is estimated based on entropy, and then the ciphertext length field , Locate the ciphertext border, and identify the ciphertext domain. The experimental results show that this method can effectively identify the protocol ciphertext field only by relying on the data traffic of the network and has a high accuracy.