P2P流量逐渐占据了互联网主要流量,在对Internet起巨大推动作用的同时,也带来了因资源过度占用而引起的网络拥塞以及安全隐患等问题,妨碍了正常的网络业务的开展。介绍了各种P2P流量识别方法及特点;然后提出一种基于双重流传输特性的局域网内P2P流量检测方法,即基于连续动态端口变化和P2P应用独特的上下行流量比率特征。该方法的创新之处在于仅使用一部分包基本统计信息,无需检测数据净荷就可以识别P2P流量。实验结果显示该方法克服了传统的基于payload特征的方法不能检测加密和未知P2P应用的缺点,具有较高检测效率和合适的检测精度。
P2P traffic has taken great portions in the network traffic.While having a significant impact on the Internet,it brings serious problems such as network congestion and traffic hindrance caused by the excessive occupation in the bandwidth.Introduces methods in identifying P2P traffic and their characters,then proposes a method of P2P traffic identifying in local area network based on two-fold traffic transmission features,namely,successive port change and its unique character in the ratio of upload and download traffic volume.The novelty of the proposed method is that it only utilizes some basic statistical information of packets instead of the inspection of data payload.Experimental results show that the method has achieved some improvements in identifying payload-encrypted and unknown P2P traffic which is hard for traditional payload-method to fulfill and has low cost and proper accuracy.