作者: Xuan-min Lu , Jiang Pei , Ya-jian Zhou
DOI: 10.1109/ICMSS.2010.5575639
关键词:
摘要: Random port, blurred protocol features, as well HTTP tunneling technology have become more and popular in the new P2P applications. It makes current traffic identification methods based on features or deep packet inspection increasingly ineffective. To resolve this problem, a model node's status is proposed paper. Through multi-level modules, obtained stored into Hash table, trusted list created by mapping feedback to end of identification. Moreover, definition active factor, incremental factor link cache can help identify generated port hopping encryption quickly effectively.