期刊文献+

基于收发平衡判定的TCP流量回放方法 被引量:6

A New Method for Interactive TCP Traffic Replay Based on Balance-Checking Between Transmitted and Received Packets
下载PDF
导出
摘要 基于真实网络流量的互动式回放测试是当前针对防火墙、IPS等串接型安全设备进行测评的最新方法.文中在分析现有基于状态判定的TCP流量互动式回放方法基础之上,引入收发平衡机制,提出了一种基于收发平衡和状态判定相结合的新的TCP流量回放方法.通过在发送TCP数据包前优先进行收发平衡判定将数据包发送出去,提出的方法能够有效减少TCP流量在发送过程中的状态判定开销,提高回放性能.对引入收发平衡机制前后的TCP流量回放方法的差异进行了分析比较.从单个TCP会话特性、并发会话流量特性、网络传输延迟与丢包等角度分析验证了影响引入收发平衡机制后的算法有效性的因素.实际流量实验表明,文中所提方法在回放TCP流量时性能有显著提升,适用于在更大规模的流量环境下对防火墙、IPS等串接型网络安全设备进行测评. Interactive network traffic replay is the newest method for testing and evaluation ot network devices such as Firewalls, IPSes, routers, switches, etc. Currently state-checking method is used for interactive TCP traffic replay. This paper proposes a new method for interac- tive TCP traffic replay which is based on the balance status between transmitted and received packets. By checking the balance conditions before sending out TCP packets, the method can sig- nificantly reduce the cost of state-checking and enhance the replay performance. The authors made a comparison on the differences of replay methods when introducing the balance mechanism. The efficiency of the method is also investigated and evaluated from aspects of a single TCP session, multi-session traffic, packet losses and latency. Experimental results show that the method outperforms the original state-checking method when replaying actual TCP traffics.
出处 《计算机学报》 EI CSCD 北大核心 2009年第4期835-846,共12页 Chinese Journal of Computers
基金 国家自然科学基金(60574087) 国家“八六三”高技术研究发展计划项目基金(2007AA01Z464,2007AA01Z475,2007AA01Z480,2008AA01Z415) 教育部博士点基金(20070698107) 陕西省自然科学基金(2006F46) 西安市科技计划(zx06026)资助~~
关键词 网络安全设备测评 流量回放 互动式TCP流量回放 状态判定 收发平衡 testing and evaluation of network security devices network traffic replay interactive TCP traffic replay state based method balance checking
  • 相关文献

参考文献8

  • 1Danzig Peter B, Jamin Sugih. tcplib: A library of TCP internetwork traffic characteristics. Computer Science Department, University of Southern California: Technical Report USC-CS- 91-495, 1991
  • 2Hong S, Wong F, Wu S Felix, Lilja B, Yohansson Tony Y, Johnson H, Nelsson A. TCPtransform: Property-oriented TCP traffic transforraation//Proceedings of the GI SIG SIDAR Conference on Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA). Vienna, Austria, 2005: 222-240
  • 3Nicol David M, Yan Guanhua. Simulation of network traffic at coarse time-scales//Proceedings of the 19th Workshop on Parallel and Distributed Simulation (PADS'05). Monterey, CA, 2005: 141-150
  • 4Sommers J, Barford P. Self-configuring network traffic generation//Proceedings of the 4th ACM SIGCOMM Conference on Internet Measurement. Taormina, Sicily, Italy, 2004:68-81
  • 5Nieol David M, Yan Guanhua. High-performance simulation of low-resolution network flows. Simulation, 2006, 82 (1) : 21-42
  • 6Hong S, Wu S. Felix: On interactive Internet traffic replay// Proceedings of the Recent Advances in Intrusion Detection. Seattle, Washington, USA, 2005:247-264
  • 7Cheng Y, HOlzle U, Cardwell N, Savage S, Voelker Geoffrey M. Monkey see, monkey do: A Tool for TCP Tracing and Replaying//Proceedings of the USENIX Annual Technical Conference. General Track. Boston, MA, USA, 2004:87-98
  • 8Wright Gary R,Stevents W Richard.TCP/IP详解协议.范建华等译.机械工业出版社,2000.

同被引文献70

引证文献6

二级引证文献10

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部