网络协议分析可以帮助安全人员分析网络漏洞。但网络协议分析面临着协议种类越来越多、协议状态空间越来越复杂的问题。首先提出了基于基函数的网络协议结构表征方法,然后在此基础上给出了基于基函数组合模式的分层协议分析方法。之后针对私有协议,提出了一种可自学习的基函数及其组合模式扩展方式。最后给出了基于基函数的网络协议分析流程。性能分析实验表明提出的方法优于传统的匹配方法和统计方法。
To analyses networks, security administrators usually use protocol analysis technologies. But there are many limitations on the existing technologies. Such as too many protocol types, complicated state space of protocol and so on. To solve the problem, a new description method of protocol structure is presented by base--function firstly. Then, a protocol analysis method base on it is proposed. To analyses the private protocols, a new self--learning algorithm is discussed. Finally, the flow of protocol analysis based on base-- function is given. Experiment results show the efficiency of presented method.