A new method is proposed to effectively identify and locate the abnormal network flows based on the abnormal changes of the flow statistics and the incomplete flows. The method bases on the bidirectional flow model
and analyzes the interactive features of different network flows. A hash function in the structure of the connection degree sketch is designed by using the Chinese remainder theorem
so that the source of the abnormal behaviors can be accurately and timely achieved
and the users'information is obtained from the abnormal flows in the high-speed networks. The dynamic and soft isolation method is used to control the abnormal behaviors and hence to slow down the spread speed of the abnormal behaviors. The experimental results in an actual network show that the proposed method is efficient in improving both the detection accuracy and speed for most kinds of abnormal behaviors. At the same time
the source of the abnormal flow is exactly located
and it is helpful to control the spread of the abnormal behaviors.
关键词
Keywords
references
MOORE D, SHANNON C. Code-red: a case study on the spread and victims of an internet worm[C]∥Proceedings of the 2002 ACM SICGOMM Internet Measurement Workshop. New York, NY, USA:ACM, 2002:273-284.
KIENZLE M, ELDER M. Recent worms: a survey and trends[C]∥Proceedings of the ACM CCS Workshop on Rapid Malicious Code. New York, NY, USA:ACM, 2003:1-10.
STANIFORD S, PAXSON V, WEAVER N, et al. How to own the internet in your spare time [C]∥Proceedings of the 11th USENIX Security Symposium. Berkeley, CA, USA: USENIX Association, 2002:149-167.
DOULIGERIS C, MITROKOTSA A. DDoS attacks and defense mechanism: classification and state of the art [J].Computer Networks, 2004, 44(4):643-666.
PENG Tao, LECKIE C, RAMAMOHANARAO K. Survey of network based defense mechanisms: countering the DoS and DDoS problems [J].ACM Computing Survey, 2007, 39(l): l-42.
XIAO Zhixin, YANG Yuexiang, YANG Lin. An anomaly traffic detection and network defending system based on NetFlow [J]. Microelectronics and Computer, 2006, 23(5):209-213.
KIM M S, KONG H J, HONG S C, et al. A flow-based method for abnormal network traffic detection [C]∥Proceedings of the Network Operations and Management Symposium. Piscataway, NJ, USA: IEEE, 2004:599-612.
KRISHNAMURTHY B, SEN S, ZHANG Yin, et al. Sketch-based change detection: methods, evaluation, and applications[C]∥Proceedings of the ACM SIGCOMM Internet Measurement Conference. New York, NY, USA:ACM, 2003:234-247.
GIBBONS P B, MATIAS Y. Synopsis structures for massive data sets[C]∥Proceedings of the 10th Annual ACMSIAM Symposium on Discrete Algorithms. Philadelphia, PA, USA: Society for Industrial and Applied Mathematics, 1999: 909-910.
MUTHUKRISHNAN S. Data streams: algorithms and applications [M].Boston, MA, USA: Now Publishers Inc., 2003.[11] 冯文峰,黄永峰,李星. 可逆概要数据结构[J].清华大学学报,2008,48(10):1625-1628.
FENG Wenfeng, HUANG Yongfeng, LI Xing. Reversible sketch data structure [J].Journal of Tsinghua University, 2008, 48(10):1625-1628.
SCHWELLER R, LI Zhichun, CHEN Yan, et al. Reversible sketches: enabling monitoring and analysis over high-speed data streams [J].Transactions on Networking, 2007, 15(5):1059-1072.
ZHAO Qi, KUMAR A, XU Jun. Joint data streaming and sampling techniques for detection of super sources and destinations[C]∥Proceedings of ACM SIGCOMM Internet Measurement Conference. New York, NY, USA: ACM, 2005:77-90.
GUAN Xiaohong, WANG Pinghui, QIN Tao. A new data streaming method for locating hosts with large connection Degree [C]∥Proceedings of IEEE Global Communications Conference. Piscataway, NJ, USA: IEEE, 2009:6421-6426.
STALLINGS W. Cryptography and network security: principles and practice [M].4th ed. Upper Saddle River, NJ,USA: Prentice-Hall, 1998.
ZOU C C, GONG Weibo, TOWSLEY D. Worm propagation modeling and analysis under dynamic quarantine defense.[C]∥Proceedings of ACM Workshop on Rapid Malcode. New York, NY, USA:ACM,2003: 51-60.