J4 ›› 2012, Vol. 39 ›› Issue (3): 149-153+165.doi: 10.3969/j.issn.1001-2400.2012.03.024

• Original Articles • Previous Articles     Next Articles

IP protocol identification method using the pattern match and check sum

YANG Jie1;LIU Congfeng2   

  1. (1. School of Commun. and Info., Xi'an Univ. of Posts & Telecommunications, Xi'an  710121, China;
    2. Research Inst. of Electronic Countermeasures, Xidian Univ., Xi'an  710071, China)
  • Received:2011-03-24 Online:2012-06-20 Published:2012-07-03
  • Contact: YANG Jie E-mail:yangjie@xupt.edu.cn

Abstract:

In order to reduce the probability of report mistakes and pretermission which is likely to happen, and to improve the nicety of explicating application-level protocols in an intrusion detection system, a method is proposed to identify the IP protocol using the pattern match algorithm and IP header check sum calculation for Ethernet data packs. Firstly, Ethernet data packs are matched with some static characters of the IP header in the proposed method, and then IP protocol check sum calculation is done. As a result, whether the type that the data packs belong to is IP protocol or not can be identified finally. Under the Visual C++software condition, simulations prove the validity and reliability of the proposed method by running the simulated programme based on the data swatch which has been listed. And so the correctness of identifying upper protocols in the future is able to be ensured.

Key words: intrusion detection, IP protocol identification, pattern match, check sum