MLchartDataset catalogue

Patent · US2011051614A1 · A1 · US

Method and device of identifying the payload of a data packet in a tcp stream

(11) Publication number
US2011051614A1
(21) Application number
12/869,828
(22) Filing date
2010-08-27
(30) Priority date
2009-08-28
(43) Publication date
2011-03-03
(51) IPC
H04L 12/26
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 63/0245, 63/123, 67/104, 69/22
(73) Assignee
International Business Machines Corp
(72) Inventors
Li Li; Jia Jia Wen; Zhe Xiang; Yi Xin Zhao
(54) Title
Method and device of identifying the payload of a data packet in a tcp stream
(57) Abstract

A method and device of identifying payload of a data packet in a TCP stream. The method includes the steps of: calculating a payload signature according to information in header of the data packet in the TCP stream; comparing the payload signature with a pre-stored file signature; determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. The present invention can monitor and identify TCP streams by using a more efficient and lower cost solution.

Full text
View on Google Patents

Claims (1)

  1. A method of identifying payload of a data packet in a TCP stream, comprising: inspecting the TCP stream to obtain the data packet in the TCP stream; calculating a payload signature according to information in header of the data packet in the TCP stream; and comparing the payload signature with a pre-stored file signature; determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. 2. The method according to claim 1, wherein information in the header of the data packet, which is used for calculating the payload signature, comprises a TCP header and a pseudo header. 3. The method according to claim 2, wherein the TCP header comprises a checksum, wherein the checksum is generated based on fields in the TCP header, the payload, and the pseudo header. 4. The method according to claim 3, wherein calculating the payload signature according to information in the header of the data packet in the TCP stream further comprises: removing from the checksum portions of the checksum which correspond to the TCP header and the pseudo header; and obtaining the payload signature. 5. The method according to claim 4, wherein removing from the checksum portions of the checksum which correspond to the TCP header and the pseudo header further comprises: bitwise-negating the checksum subsequent to subtracting 1 therefrom; obtaining value A; obtaining value B by adding complement of fields except the checksum in the TCP header and of fields in the pseudo header in the unit of 16 bits; adding 1 to value B subsequent to bitwise-negating value B; and obtaining resultant value B′; and adding value A and value B′. 6. The method according to claim 1, further comprising: dividing in advance the file into multiple portions of a specific length, wherein one of the portions of specific length can be transmitted in a data packet and is used as the payload of the data packet; generating a file signature for at least one part of the portions of specific length, wherein the file signature for at least one part of the portions of specific length is generated in the same way as calculating a payload signature according to information in the header of the data packet in the TCP stream; and storing the file signature generated for the at least one part of the portions of specific length. 7. The method according to claim 1, wherein the TCP stream is a P2P stream. 8. A device of identifying payload of a data packet in a TCP stream, comprising: inspection means for inspecting the TCP stream to obtain a data packet in the TCP stream; calculation means for calculating a payload signature according to information in header of the data packet in the TCP stream; comparison means for comparing the payload signature with a pre-stored file signature; determining means for determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. 9. The device according to claim 8, wherein information in the header of the data packet, which is used for calculating the payload signature, comprises a TCP header and a pseudo header. 10. The device according to claim 9, wherein the TCP header comprises a checksum, wherein the checksum is generated based on fields in the TCP header, the payload, and the pseudo header. 11. The device according to claim 9, wherein the calculation means further removes from the checksum portions of the checksum, which correspond to the TCP header and the pseudo header, and thus obtaining the payload signature. 12. The device according to claim 10, wherein the calculation means removes from the checksum portions of the checksum which correspond to the TCP header and the pseudo header further comprises: bitwise-negating the checksum subsequent to subtracting 1 therefrom, and thus obtaining value A; obtaining value B by adding complement of fields except the checksum in the TCP header and of fields in the pseudo header in units of 16 bits, adding 1 to value B subsequent to bitwise-negating value B, and thus obtaining value B′; adding value A and value B′. 13. The device according to claim 8, further comprising: means for dividing in advance the file into multiple portions of a specific length, wherein one of the portions of a specific length can be transmitted in a data packet and is used as the payload of the data packet; means for generating a file signature for at least one part of the portions of specific length, wherein the file signature for at least one part of the portions of specific length is generated in the same way as calculating a payload signature according to information in the header of the data packet in the TCP stream; and means for storing the file signature generated for the at least one part of the portions of specific length. 14. The device according to claim 8, wherein the device is a router or a switch. 15. The device according to claim 8, wherein the TCP stream is a P2P stream.

Description

1. Field of the Invention

The present invention relates to the transmission of network data. More specifically, the present invention relates to a method and device of identifying the payload of a data packet in a TCP stream.

2. Description of the Related Art

P2P (Peer-to-Peer) traffic is growing dramatically in recent years. According to a study report by CacheLogic in 2006, up to 70% of ISP (Internet Service Provider) traffic was P2P traffic.

In brief, P2P is technology for exchanging data or services directly between different computer users without a relay device, which allows an Internet user to utilize files of the other party. Each person may be directly connected to a computer of another user for a file exchange without being connected to a server for browsing and downloading. In a P2P operating mode, each client terminal acts as both a client and a server. This leads to a “flat” network model.

A P2P computer network uses diverse connectivity between participants in a network, and it leverages the cumulative bandwidth of network participants rather than conventional centralized resources, where a relatively low number of servers provide the core content to a service or application. P2P networks are typically used for connecting nodes via ad hoc mode. Such networks are quite useful for many applications. Common examples of such applications include sharing files containing audio, video, data or any content in digital format, and transferring real-time data, such as telephony media. In addition, P2P demonstrates its uses in deep search, distributed computing, cooperative work, and other aspects.

Citations (14)

  • US20020071438A1
  • US20060114939A1
  • US6728929B1
  • US7363278B2
  • US7328349B2
  • US20030204632A1
  • US7515612B1
  • US7451489B2
  • US20060168318A1
  • US20060184961A1
  • US7703138B2
  • US7856661B1
  • US8094607B2
  • US20080163288A1
Record as JSON
{
  "publication_number": "US2011051614A1",
  "country": "US",
  "kind": "A1",
  "title": "Method and device of identifying the payload of a data packet in a tcp stream",
  "abstract": "A method and device of identifying payload of a data packet in a TCP stream. The method includes the steps of: calculating a payload signature according to information in header of the data packet in the TCP stream; comparing the payload signature with a pre-stored file signature; determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. The present invention can monitor and identify TCP streams by using a more efficient and lower cost solution.",
  "claims": [
    "1. A method of identifying payload of a data packet in a TCP stream, comprising: inspecting the TCP stream to obtain the data packet in the TCP stream; calculating a payload signature according to information in header of the data packet in the TCP stream; and comparing the payload signature with a pre-stored file signature; determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. 2. The method according to claim 1, wherein information in the header of the data packet, which is used for calculating the payload signature, comprises a TCP header and a pseudo header. 3. The method according to claim 2, wherein the TCP header comprises a checksum, wherein the checksum is generated based on fields in the TCP header, the payload, and the pseudo header. 4. The method according to claim 3, wherein calculating the payload signature according to information in the header of the data packet in the TCP stream further comprises: removing from the checksum portions of the checksum which correspond to the TCP header and the pseudo header; and obtaining the payload signature. 5. The method according to claim 4, wherein removing from the checksum portions of the checksum which correspond to the TCP header and the pseudo header further comprises: bitwise-negating the checksum subsequent to subtracting 1 therefrom; obtaining value A; obtaining value B by adding complement of fields except the checksum in the TCP header and of fields in the pseudo header in the unit of 16 bits; adding 1 to value B subsequent to bitwise-negating value B; and obtaining resultant value B′; and adding value A and value B′. 6. The method according to claim 1, further comprising: dividing in advance the file into multiple portions of a specific length, wherein one of the portions of specific length can be transmitted in a data packet and is used as the payload of the data packet; generating a file signature for at least one part of the portions of specific length, wherein the file signature for at least one part of the portions of specific length is generated in the same way as calculating a payload signature according to information in the header of the data packet in the TCP stream; and storing the file signature generated for the at least one part of the portions of specific length. 7. The method according to claim 1, wherein the TCP stream is a P2P stream. 8. A device of identifying payload of a data packet in a TCP stream, comprising: inspection means for inspecting the TCP stream to obtain a data packet in the TCP stream; calculation means for calculating a payload signature according to information in header of the data packet in the TCP stream; comparison means for comparing the payload signature with a pre-stored file signature; determining means for determining the payload of the data packet in the TCP stream as belonging to a file corresponding to the pre-stored file signature, in response to a match between payload signatures of multiple data packets and the pre-stored file signature. 9. The device according to claim 8, wherein information in the header of the data packet, which is used for calculating the payload signature, comprises a TCP header and a pseudo header. 10. The device according to claim 9, wherein the TCP header comprises a checksum, wherein the checksum is generated based on fields in the TCP header, the payload, and the pseudo header. 11. The device according to claim 9, wherein the calculation means further removes from the checksum portions of the checksum, which correspond to the TCP header and the pseudo header, and thus obtaining the payload signature. 12. The device according to claim 10, wherein the calculation means removes from the checksum portions of the checksum which correspond to the TCP header and the pseudo header further comprises: bitwise-negating the checksum subsequent to subtracting 1 therefrom, and thus obtaining value A; obtaining value B by adding complement of fields except the checksum in the TCP header and of fields in the pseudo header in units of 16 bits, adding 1 to value B subsequent to bitwise-negating value B, and thus obtaining value B′; adding value A and value B′. 13. The device according to claim 8, further comprising: means for dividing in advance the file into multiple portions of a specific length, wherein one of the portions of a specific length can be transmitted in a data packet and is used as the payload of the data packet; means for generating a file signature for at least one part of the portions of specific length, wherein the file signature for at least one part of the portions of specific length is generated in the same way as calculating a payload signature according to information in the header of the data packet in the TCP stream; and means for storing the file signature generated for the at least one part of the portions of specific length. 14. The device according to claim 8, wherein the device is a router or a switch. 15. The device according to claim 8, wherein the TCP stream is a P2P stream."
  ],
  "description_excerpt": "1. Field of the Invention\n\nThe present invention relates to the transmission of network data. More specifically, the present invention relates to a method and device of identifying the payload of a data packet in a TCP stream.\n\n2. Description of the Related Art\n\nP2P (Peer-to-Peer) traffic is growing dramatically in recent years. According to a study report by CacheLogic in 2006, up to 70% of ISP (Internet Service Provider) traffic was P2P traffic.\n\nIn brief, P2P is technology for exchanging data or services directly between different computer users without a relay device, which allows an Internet user to utilize files of the other party. Each person may be directly connected to a computer of another user for a file exchange without being connected to a server for browsing and downloading. In a P2P operating mode, each client terminal acts as both a client and a server. This leads to a “flat” network model.\n\nA P2P computer network uses diverse connectivity between participants in a network, and it leverages the cumulative bandwidth of network participants rather than conventional centralized resources, where a relatively low number of servers provide the core content to a service or application. P2P networks are typically used for connecting nodes via ad hoc mode. Such networks are quite useful for many applications. Common examples of such applications include sharing files containing audio, video, data or any content in digital format, and transferring real-time data, such as telephony media. In addition, P2P demonstrates its uses in deep search, distributed computing, cooperative work, and other aspects.",
  "cpc": [
    "H04L 63/0245",
    "H04L 63/123",
    "H04L 67/104",
    "H04L 69/22"
  ],
  "ipc": [
    "H04L 12/26"
  ],
  "assignees": [
    "International Business Machines Corp"
  ],
  "inventors": [
    "Li Li",
    "Jia Jia Wen",
    "Zhe Xiang",
    "Yi Xin Zhao"
  ],
  "filing_date": "2010-08-27",
  "publication_date": "2011-03-03",
  "priority_date": "2009-08-28",
  "application_number": "US-86982810-A",
  "family_id": "43624766",
  "cited_by_count": 18,
  "citations": [
    "US20020071438A1",
    "US20060114939A1",
    "US6728929B1",
    "US7363278B2",
    "US7328349B2",
    "US20030204632A1",
    "US7515612B1",
    "US7451489B2",
    "US20060168318A1",
    "US20060184961A1",
    "US7703138B2",
    "US7856661B1",
    "US8094607B2",
    "US20080163288A1"
  ]
}

Record 5,400 of 8,000 in Patents full text (MLC-0201). Request the full dataset.