摘要
针对网络威胁正从网络层转化到应用层的情况,通过对Sockets函数的拦截,得到运输层的TCP数据流和UDP数据报,并对应用层协议进行识别和分析,实现对应用层非标准协议的监测.提出了一种应用层非标准协议通用的监测方法,通过实验验证了其可用性和可靠性.
Network layer threat from the network application layer into the trend is very clear. The application layer monitoring is imminent. In this paper, through the interception of Sockets function, the transport layer of TCP and UDP data flow data report is obtained. Through the application of the identification and analysis of the protocol, it is necessary to monitor the application layer monitoring of non-standard protocol. A universal application layer of non-standard protocol the monitoring method is proposed, experimental verification of its availability and reliability are demonstrated with experiments.
出处
《重庆工学院学报(自然科学版)》
2008年第9期108-111,共4页
Journal of Chongqing Institute of Technology
基金
国家863高技术研究发展计划资助项目(2007AA01Z445)
关键词
非标准协议
数据采集
监测
non-standard protocol
data acquisition
monitoring