PSO-based feature extraction of unknown protocol data frame

被引:3
作者
Liu, Zhiguo [1 ]
Zhang, Jiaojiao [1 ]
Wang, Lin [2 ]
Feng, Jianxin [1 ]
Ding, Yuanming [1 ]
Ren, ChangQing [1 ]
机构
[1] Dalian Univ, Commun & Network Lab, Dalian 116622, Liaoning, Peoples R China
[2] Dalian Univ, Sch Environm & Chem Engn, Dalian 116622, Liaoning, Peoples R China
关键词
Feature extraction; Protocol identification; PSO; Association rule;
D O I
10.1007/s00607-022-01118-w
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In today's network information confrontation, due to security reasons, the protocols used by both parties are often undisclosed and the protocol format is unknown, and the communication data is in the form of the continuous and irregular bitstream. How to extract features without prior knowledge is an urgent problem to be solved. Therefore, this study proposes a method for the feature extraction of unknown protocol data frames based on the particle swarm optimization (PSO) algorithm to address the problem of low adaptability and low accuracy of frequent thresholds. Given the features of the bitstream data frames, the proposed method segments the bitstream data through Zipf's law. The PSO algorithm is employed to adapt the frequent threshold to the uncertainty of the unknown protocols, and the short frequent sequence is then obtained under the adaptive threshold. The continuous location information is then applied to splice the excavated short frequent sequences to determine the final frequent sequence set. To filter out the effective association rules, the chi-squared test is conducted to analyze the association rules mined between frequent sequences. According to the simulation results, the proposed method managed to achieve the frequent extraction of adaptive thresholds in different datasets, whereas its accuracy was higher than that of the comparison algorithm. Moreover, the method proposed in this paper has certain practical significance for theoretical research and application in this field.
引用
收藏
页码:131 / 149
页数:19
相关论文
共 25 条
[1]  
Agrawal Mayank, 2015, 2015 International Conference on Communication Networks (ICCN), P395, DOI 10.1109/ICCN.2015.76
[2]  
Aparna UR, 2016, PROCEEDINGS OF 2016 ONLINE INTERNATIONAL CONFERENCE ON GREEN ENGINEERING AND TECHNOLOGIES (IC-GET)
[3]  
Cai L, 2017, 2017 IEEE 2ND INTERNATIONAL CONFERENCE ON BIG DATA ANALYSIS (ICBDA), P216
[4]  
Feddaoui I, 2016, PROCEEDINGS OF THE 2016 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING ASONAM 2016, P752, DOI 10.1109/ASONAM.2016.7752322
[5]  
Fen L, 2012, IEEE 2012 8 INT C CO, P674
[6]   Optimization Algorithm Improvement of Association Rule Mining Based on Particle Swarm Optimization [J].
Feng, Hao ;
Liao, Rongtao ;
Liu, Fen ;
Wang, Yixi ;
Yu, Zheng ;
Zhu, Xiaojun .
2018 10TH INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION (ICMTMA), 2018, :524-529
[7]   Feature Extraction Optimization for Bitstream Communication Protocol Format Reverse Analysis [J].
Hei, Xinhong ;
Bai, Binbin ;
Wang, Yichuan ;
Zhang, Li ;
Zhu, Lei ;
Ji, Wenjiang .
2019 18TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS/13TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (TRUSTCOM/BIGDATASE 2019), 2019, :662-669
[8]  
Ju Y, 2014, COMPUTER MEASUREMENT
[9]  
Kim M. S., 2018, P NOMS IEEE IFIP NET, P1
[10]  
Lei Y, 2020, 2020 12 INT C COMMUN