分析了未知协议的使用对网络安全监管带来的挑战,总结了现有已知协议识别技术存在的弊端;综述了现有面向比特流的协议识别研究领域所涉及的主要内容,重点研究了现有未知协议格式推断方法,包括频繁模式挖掘、关联规则挖掘、比特流帧切分以及协议格式推断并总结了各自的特点;最后讨论了下一步的研究方向。
This paper analyzed the challenges presented by the use of unknown protocol for the network security supervision, collected and introduced the insufficiency of the existing protocol identification technology. It presented a comprehensive sur- vey of the existing main contents of bit stream oriented protocol identification research field, studied the method of inferring the format of unknown protocol including frequent pattern mining, association rule mining, frame segmentation and protocol format inferring, introduced and analyzed respectively features of these techniques. Finally it discussed the trend of research and application.