학술논문

Network Protocol Reverse Parsing Based on Bit Stream
Document Type
Conference
Source
2021 8th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)/2021 7th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom) CSCLOUD-EDGECOM Cyber Security and Cloud Computing (CSCloud)/2021 7th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom), 2021 8th IEEE International Conference on. :83-90 Jun, 2021
Subject
Communication, Networking and Broadcast Technologies
Computing and Processing
Cloud computing
Protocols
Conferences
Clustering algorithms
Syntactics
Security
Computer crime
cyber security
reverse parsing
association rules
hierarchical clustering
pattern recognition
Language
ISSN
2693-8928
Abstract
The network security problem brought by the cloud computing has become an important issue to be dealt with in information construction. Since anomaly detection and attack detection in cloud environment need to find the vulnerability through the reverse analysis of data flow, it is of great significance to carry out the reverse analysis of unknown network protocol in the security application of cloud environment. To solve this problem, an improved mining method on bitstream protocol association rules with unknown type and format is proposed. The method combines the location information of the protocol framework to make the frequent extraction process more concise and accurate. In addition, for the frame separation problem of unknown protocol, we design a hierarchical clustering algorithm based on Jaccard distance and a frame field delimitation method based on the proximity of information entropy between bytes. The experimental results show that this technology can correctly resolve the protocol format and realize the purpose of anomaly detection in cloud computing, and ensure the security of cloud services.