针对单独的深度数据包检测(Deeppacketinspection,DPI)技术无法识别加密报文,以及基于流量特征识别方法对流量检测的模糊性等问题,采用DPI和基于流量特征相结合的方法来对Ares协议进行精确的识别,以提高对Ares协议的识别效果,实验表明准确率可以达到97%以上。
In this paper we find a method to accurately identify the Ares protocol by using DPI combined with DFI technology. In this way, it not only overcome the shortage of DPI technology which can' t identify the encrypted flows and data flows, but also solve the imprecision of the DFI technology, so that those couples can work smoothly, and make up with each other, and also improve the identification effect, the accuracy rate can up to 97%.