Journal of University of Chinese Academy of Sciences >
Cyberspace device identification based on K-means with cosine distance measure
Received date: 2016-01-07
Revised date: 2016-03-17
Online published: 2016-07-15
Since the traditional web fingerprinting methods are limited to identification of mainstream web server softwares, a kind of cyberspace device identification model based on K-means with cosine distance measure is proposed.Firstly, identification model is designed and verification method is determined.Secondly, the header fields and the status code of HTTP response are selected as characteristics of terminal device and then the characteristics are transformed into 32-dimensional feature vector by feature extraction and vectorization.Thirdly, cosine distance function is selected as similarity measuring function in K-means.Finally, experiment algorithm process is designed according to the identification model and the experiments for unlabeled samples and labeled samples are carried out.The results show that the identification model works for many kinds of terminal devices, including wireless router, web camera, and intelligent switch, and has high accuracy rate and low omission rate.
Key words: cyberspace; terminal device; K-means; cosine measure; fingerprinting
CAO Laicheng , ZHAO Jianjun , CUI Xiang , LI Ke . Cyberspace device identification based on K-means with cosine distance measure[J]. Journal of University of Chinese Academy of Sciences, 2016 , 33(4) : 562 -569 . DOI: 10.7523/j.issn.2095-6134.2016.04.019
[1] ZoomEye.网络设备统计分析 .(2015-12-31) .https://www.zoomeye.org/statistic/device.
[2] Gallagher S.Backdoor in wireless DSL routers lets attacker reset router, get admin .(2014-01-03) 12-31].http://arstechnica.com/security/2014/01/backdoor- in-wireless-dsl-routers-lets-attacker-reset-router-get-admin/.
[3] Chirgwin R.Hacker backdoors Linksys, Netgear, Cisco and otheh routers .(2014-01-06) .http:// www.theregister.co.uk/2014/01/06/hacker_backdoors_linksys_netgear_cisco_and_other_routers/.
[4] 国家互联网应急中心.关于多款D-LINK路由器产品存在后门漏洞的情况通报 .(2013-10-25) .http://www.cert.org.cn/publish/main/9/2013/20131025152943288740930/20131025152943288740930_.html.
[5] Singh D, Sinha R, Songara P, et al.Vulnerabilities and attacks targeting social networks and industrial control systems[J].Eprint Arxiv, 2014, 4(1):133-142.
[6] 彭勇, 江常青, 谢丰, 等.工业控制系统信息安全研究进展[J].清华大学学报:自然科学版, 2012, 52(10): 1 396-1 408.
[7] 卢慧康.工业控制系统脆弱性测试与风险评估研究 .上海:华东理工大学, 2014.
[8] Shah S.An introduction to HTTP fingerprinting .(2004-05-19) .http://net-square.com/httprint_paper.html.
[9] Lee D, Rowe J, Ko C, et al.Detecting and defending against Web-server fingerprinting //CSAC 2002: 2002 Computer Security Applications Conference.United States: IEEE Computer Society, 2002: 321-330.
[10] 杨可新, 鞠九滨.利用Web指纹进行服务映射[J].计算机工程与应用, 2004, 40(4): 7-9.
[11] Fyodor.Remote OS detection via TCP/IP stack fingerprinting[J].Phrack Magazine, 1998, 17(3): 1-10.
[12] 吴少华, 孙丹, 胡勇.基于贝叶斯理论的Web服务器识别[J].计算机工程, 2015, 41(7): 190-193,198.
[13] 刘三民, 孙知信, 刘余霞.基于K均值集成和SVM的P2P流量识别研究[J].计算机科学, 2012, 39(4): 46-48,74.
[14] 陈磊磊.不同距离测度的K-Means文本聚类研究[J].软件, 2015, 36(1): 56-61.
/
| 〈 |
|
〉 |