Design and Implementation of a Deep Packet Inspection System

博士 === 國立成功大學 === 電腦與通信工程研究所 === 100 === Network services and applications are parts of people’s life today. With many business transactions keeping going in the Internet, to manage the network services is an important issue. Establishment of traffic classification is important for management of the...

Full description

Bibliographic Details
Main Authors: Ming-YiLiao, 廖明沂
Other Authors: Chu-Sing Yang
Format: Others
Language:en_US
Published: 2012
Online Access:http://ndltd.ncl.edu.tw/handle/47968974053998385858
id ndltd-TW-100NCKU5652109
record_format oai_dc
spelling ndltd-TW-100NCKU56521092015-10-13T21:38:04Z http://ndltd.ncl.edu.tw/handle/47968974053998385858 Design and Implementation of a Deep Packet Inspection System 深入網路封包內容檢測系統之設計與實作 Ming-YiLiao 廖明沂 博士 國立成功大學 電腦與通信工程研究所 100 Network services and applications are parts of people’s life today. With many business transactions keeping going in the Internet, to manage the network services is an important issue. Establishment of traffic classification is important for management of the network service. Classifying the network traffic based on port number is not enough, because some network services do not use fixed port. Such as Botnet and phishing site use the standard protocol to transmit data. Therefore, Deep Packet Inspection system is used to classify the network traffic for network traffic statistics, quality of service, and network security management. In this dissertation, we propose a new style of deep packet inspection system named Net-DPI and classify the patterns of network protocols based on the offset in the payload. The pattern table is constructed with trie structure for reducing the affection by the amount of patterns. In rule matching, we previously build the relationship between patterns and rules to simplify the complexity of rule matching. The proposed algorithms are for reducing the time cost of traffic classification. This system is implemented in Linux kernel. It provides traffic classification and sends the classified network services and connection information to the network management system for sharing to achieve the purpose of zone network defense. Chu-Sing Yang 楊竹星 2012 學位論文 ; thesis 102 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 博士 === 國立成功大學 === 電腦與通信工程研究所 === 100 === Network services and applications are parts of people’s life today. With many business transactions keeping going in the Internet, to manage the network services is an important issue. Establishment of traffic classification is important for management of the network service. Classifying the network traffic based on port number is not enough, because some network services do not use fixed port. Such as Botnet and phishing site use the standard protocol to transmit data. Therefore, Deep Packet Inspection system is used to classify the network traffic for network traffic statistics, quality of service, and network security management. In this dissertation, we propose a new style of deep packet inspection system named Net-DPI and classify the patterns of network protocols based on the offset in the payload. The pattern table is constructed with trie structure for reducing the affection by the amount of patterns. In rule matching, we previously build the relationship between patterns and rules to simplify the complexity of rule matching. The proposed algorithms are for reducing the time cost of traffic classification. This system is implemented in Linux kernel. It provides traffic classification and sends the classified network services and connection information to the network management system for sharing to achieve the purpose of zone network defense.
author2 Chu-Sing Yang
author_facet Chu-Sing Yang
Ming-YiLiao
廖明沂
author Ming-YiLiao
廖明沂
spellingShingle Ming-YiLiao
廖明沂
Design and Implementation of a Deep Packet Inspection System
author_sort Ming-YiLiao
title Design and Implementation of a Deep Packet Inspection System
title_short Design and Implementation of a Deep Packet Inspection System
title_full Design and Implementation of a Deep Packet Inspection System
title_fullStr Design and Implementation of a Deep Packet Inspection System
title_full_unstemmed Design and Implementation of a Deep Packet Inspection System
title_sort design and implementation of a deep packet inspection system
publishDate 2012
url http://ndltd.ncl.edu.tw/handle/47968974053998385858
work_keys_str_mv AT mingyiliao designandimplementationofadeeppacketinspectionsystem
AT liàomíngyí designandimplementationofadeeppacketinspectionsystem
AT mingyiliao shēnrùwǎnglùfēngbāonèiróngjiǎncèxìtǒngzhīshèjìyǔshízuò
AT liàomíngyí shēnrùwǎnglùfēngbāonèiróngjiǎncèxìtǒngzhīshèjìyǔshízuò
_version_ 1718067828434665472