期刊文献+

运用网络流量自相似分析的网络流量异常检测 被引量:12

Abnormity Detection of Network Traffic Applied Self-Similarity Analysis of Network Traffics
在线阅读 下载PDF
导出
摘要 网络流量自相似分析有聚集方差法、R/S分析法、周期图法和Whittle法。基于网络流量自相似分析的网络流量异常检测采用正常流量模型、对网络流量自相似性参数Hurst及其时变函数H(t)进行分析。对网络流量进行实时限幅及使用数据库统计,通过检测自相似性变化,判断网络流量是否异常。分布式拒绝服务攻击试验表明,此法比传统的基于特征匹配的网络流量异常检测法在识别精度与实时性上有较大提高。 Self-similarity analysis of network traffic (SSANT) includes aggregated variance, R/S analysis, periodic diagram and whittle methods. The normal model of network traffic was adopted in abnormity detection of network traffic based on SSANT. Self-Similarity Hurst parameter and time variable function H(t) of network traffics was analyzed. Network traffic was limited in real time and the abnormity characteristic was refined with database statistical analysis. Through detection of self-similarity change was measured, then determine whether the current traffic is normal. Attack test of distributed decline service shows that abnormity detection of network traffic based on SSANT is more reliable on the recognition of network traffic abnormity than any other traditional method based on character recognition.
出处 《兵工自动化》 2003年第6期28-31,共4页 Ordnance Industry Automation
关键词 入侵检测 网络流量 自相似性 分布式拒绝服务攻击 Intrude detection Network traffic Self-similarity analysis Distributed decline service
  • 相关文献

参考文献2

二级参考文献9

  • 1Fan Y H,Performance analysis of ATM switches with self-similar traffic,1996年
  • 2Huang C C,ICC’95,1995年
  • 3Wang Q L,IEEE/ACM Trans on Networking,1993年,1卷,2期,230页
  • 4Huang C C,ACM Comput Commun Rev,25卷,4期,114页
  • 5蔡弘,96’中国智能自动化学术会议,1996年
  • 6蔡弘,IEEE ICIT’96,1996年
  • 7Cai Hong,IEEE Int Conf on Industrial Technology,1996年,791页
  • 8秦前清,实用小波分析,1994年
  • 9蔡弘,陈惠民,李衍达.自相似业务模型——通信网络突发业务建模的新方法[J].通信学报,1997,18(11):51-59. 被引量:28

共引文献39

同被引文献87

引证文献12

二级引证文献95

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部