Background technology
Along with the development of Internet technology and scale, access way increases, the expansion of terminal diversity and COS, and data stream type and number in network all sharply increase.Existing stream identification method is when in the face of new types of data stream type, and as P2P, multimedia and various encrypting traffic, all exposed various deficiencies.
The stream identification method of conventional internet, according to the network layer at its place, can be divided into application layer and transport layer., itself there is the poor defect of autgmentability, thereby cannot adapt to the demand of application program miscellaneous in integrated identification network in the stream identification method realizing in application layer.
The stream identification method realizing in transport layer comprises three classes: a class is the stream identification based on port; Two classes are the identification methods based on data flow; Three classes are that data statistics and sign are carried out in the connection based on setting up.But, in view of the intrinsic defect of conventional internet framework, cannot effectively manage the connection of setting up and the data flow of transmission, all there is more or less the defect of practicality and applicability aspect in the scheme of these traffic identifier.
The framework of integrated identification network is divided into two-layer, comprises switching and routing layer and Pervasive Service layer.Connect sublayer, with respect to the concept of the transport layer of conventional internet, the concept of a logic just in integrated identification network, for being connected mutual route layer and Pervasive Service layer.Connection identifier is that this connects sublayer for the sign of logical connection information and resource.Connection identifier is that the resource in service acquisition procedure and information are identified.
The appearance of connection identifier, the management function that can facilitate for the transmitting procedure of data flow and the link information of foundation thereof and resource.By the stream identification method based on connection identifier in this patent, can regulate and control more easily attack and the destruction of integrated identification network data flow, especially malicious data flow simultaneously.
Summary of the invention
The object of the present invention is to provide a kind of stream identification method that is applicable to integrated identification network, for the data flow in differentiation and management integration marked network is given security.The present invention utilizes the identification function of connection identifier to logical connection information and resource in integrated identification network, by the differentiation of data flow and identification function by the analysis of connection identifier and management are realized.
In the present invention, comprise the feature of the data flow that statistics obtains in satellite information corresponding to connection identifier, these features have the advantage of single stream recognition method in the past that is incorporated into, and possess again the possibility of comprehensive measurement data flow feature simultaneously.These statistical natures mainly comprise the port information that data stream transmitting is used, data stream size, and transmission frequency, data package size and interval time, the transmitting continuous time, retransmits frequency.
By the classification of connection identifier satellite information is processed, the feature that the result of classification is had as connection identifier.Therefore to the sign of integrated identification network data flow and differentiation, be, the analysis based on to connection identifier feature.The feature of connection identifier can reflect the data traffic feature that logic connects.Because the introducing of connection identifier has facilitated integrated identification network to transmission data and the management that connects, the stream identification based on connection identifier just can be carried out Accurate Analysis from multiple angles.
Embodiment
Relevant the technical content and a detailed description, existing accompanying drawings is as follows:
Fig. 1 is the schematic diagram that in the present invention, connection identifier and satellite information thereof arrive.In Fig. 1, connection identifier is the random string of 160, the satellite information of connection identifier comprises the service requester address that logic connects, ISP address, the port that service requester is used, the port that ISP uses, the inquiry times statistics of connection identifier, the data flow traffic feature that connection identifier is corresponding.
Fig. 2 is the data flow characteristic statistics flow process based on connection identifier in the present invention.In integrated identification network, data stream transmitting relates to the connection identifier distributing into this transmission, service requester and ISP's address and port information and be the headspace of data stream statistics characteristic, also relate to the inquiry to connection identifier and satellite information map entry thereof in transmitting procedure.When carry the data flow of connection identifier while transmitting in integrated identification network, the feature that the element that can relate to by it presents is analyzed and is added up the feature of data flow.The data flow feature that statistics obtains is updated to the satellite information of connection identifier by feedback function, by the analysis of satellite information and processing, they are reflected in connection identifier and satellite information thereof.
Fig. 3 is the data structure show that the invention provides a CID satellite information, has headspace, also has QoS information, and the statistics of data characteristics can arrange in headspace.
Fig. 4 is a kind of flow process that is compatible with the data flow signature identification method based on connection identifier of existing the Internet of the concrete enforcement of the present invention.In Fig. 3, with IP_S, indicate ISP's address, IP_C indication service initiator's address, CID_Map indication connection identifier manager, Auc indicates Verification System, ASR indication access switch router, GSR indication broad sense switch router, CID indicates connection identifier, the satellite information of CID_addi indication connection identifier, the statistical module of CID_statistic indication connection identifier satellite information, CID_Proxy indicating terminal agency.
CID_statistic statistical module need to carry out model parameter training by some data groups, according to predefined data flow feature, statistical model is trained, and along with the statistics and analysis to data flow feature in network, can revise model parameter.
In integrated identification network, the implementing procedure of the stream identification method based on connection identifier comprises the following steps:
1) packet being sent by IP_C carries CID, and while transmitting in integrated identification network, the CID management node that access IP_C connects, wherein contains CID and CIDaddi, access times is added to 1, the features such as size of record data bag;
2) after access CID management node, according to the address transmission data bag of CID and CIDaddi indication;
3) packet arrives behind opposite end, and the information inspection CID management node according to carrying, adds 1 by its access times, the feature of record data bag;
4) data, when incoming terminal, are analyzed the feature of data flow, and by the result feedback of analyzing, to CID_statistic module, complete paired data flows an analytic record of feature;
5), according to the data characteristics in CID_addi, by CID_statistic statistical module parameter, this connection identifier is identified and classified.The transmitting procedure of data is exactly a process that completes the data flow characteristic statistics based on connection identifier simultaneously.
Finally it should be noted that: obviously, above-described embodiment is only for example of the present invention is clearly described, and the not restriction to execution mode.For those of ordinary skill in the field, can also make other changes in different forms on the basis of the above description.Here exhaustive without also giving all execution modes.And the apparent variation of being amplified out thus or change are still among protection scope of the present invention.