海军工程大学电气与信息工程学院,武汉,430033
网络首发:2012-02-10,
纸质出版:2012
移动端阅览
侯重远, 江汉红, 芮万智, 等. 工业网络流量异常检测的概率主成分分析法[J]. 西安交通大学学报, 2012,46(2):70-75.
A Probabilistic Principal Component Analysis Approach for Detecting Traffic Anomaly in Industrial Networks[J]. 2012, 46(2): 70-75.
针对主成分分析(PCA)法用于工业测控网络流量异常检测时存在的误报率高的问题
提出了一种基于概率主成分分析(PPCA)的检测算法.首先通过分析误报成因
建立了工业测控网络流量矩阵的PPCA模型
然后使用迭代变分贝叶斯算法辨识该模型的参数
再利用模型参数估计值求解流量矩阵的秩的分布函数并得到秩的极大似然估计值
最后以秩的跃变状况为判据进行异常流量检测.模拟攻击实验表明
该方法使漏报率平均下降了32%
从而有效降低了PCA方法的误报率.
An algorithm using probabilistic principal component analysis(PPCA)is proposed to reduce the false alarm rate of anomaly detection of industrial networks using traditional principal component analysis(PCA). A PPCA model of industrial network traffic matrix is established by analyzing the causes of false alarm. Parameters in the model are identified by using the iterative variational Bayesian algorithm
and then are used to infer the rank of the PPCA model. Traffic anomaly is finally detected by making judgement on the rank. Simulated attack experiments show that the proposed method decreases false alarm rate by 32% in average
and effectively reduces the false alarm rate of PCA method.
颜若愚,郑庆华.使用交叉熵检测和分类网络异常流量[J].西安交通大学学报, 2010, 44(6):10-15.
YAN Ruoyu, ZHENG Qinhua. Using cross entropy to detect and classify network anomalous traffic [J]. Journal of Xi'an Jiaotong University, 2010, 44(6):10-15.
LAKHINA A, CROVELLA M, DIOT C. Diagnosing network-wide traffic anomalies[C]∥Proceedings of ACM SIGCOMM 2004: Conference on Computer Communications. New York, USA: ACM, 2004: 219-230.
LAKHINA A, CROVELLA M, DIOT C. Characterization of network-wide anomalies in traffic flows[C]∥Proceedings of the 2004 ACM SIGCOMM Internet Measurement Conference. New York, USA: ACM, 2004: 201-206.
LAKHINA A, CROVELLA M, DIOT C. Mining anomalies using traffic feature distributions [J]. Computer Communication Review, 2005, 35(4): 217-228.
张文铸,刘佳, 袁坚, 等.基于PCA的对等网络流量时空特性监测[J].清华大学学报:自然科学版,2010,50(4):561-564.
ZHANG Wenzhu, LIU Jia, YUAN Jian, et al. PCA based approach for monitoring the spatial-and-temporal characteristics of P2P traffic [J].Journal of Tsinghua University:Science and Technology, 2010, 50(4): 561-564.
RUBINSTEIN B, NELSON B, HUANG L, et al. Compromising PCA-based anomaly detectors for network-wide traffic, UCB/EECS-2008-73 [R]. Berkeley, USA: UCB, 2009.
钱叶魁,陈鸣.面向PCA异常检测器的毒害攻击和防御机制[J].电子学报, 2011, 39(3):543-548.
QIAN Yekui, CHEN Ming. Poison attack and defense strategies on PCP based anomaly detector[J].Acta Electrionica Sinica, 2011, 39(3):543-548.
CHATZIGIANNAKIS V, PAPAVASSILIOU S, ANDROULIDAKIS G. Improving network anomaly detection effectiveness via an integrated multi-metric-multi-link(M3L)PCA-based approach[J].Security and Communication Networks, 2009, 2(3): 289-304.
BRAUCKHOFF D,SALAMATIAN K, MAY M. Applying PCA for traffic anomaly detection: problems and solutions[C]∥Proceedings of IEEE INFOCOM 2009. Piscataway, NJ, USA: IEEE, 2009: 2866-2870.
ZAIDI Z, HAKAMI S, MOORS T, et al. Detection and identification of anomalies in wireless mesh networks using principal component analysis [J]. Journal of Interconnection Networks, 2009, 10(4): 517-534.
ZAIDI Z R, HAKAMI S, LANDFELDT B, et al. Real-time detection of traffic anomalies in wireless mesh networks [J]. Wireless Networks, 2010,16(6):1675-1689.
BISHOP M, TIPPING E. Probabilistic principal component analysis [J]. Journal of the Royal Statistical Society,1999,61(3):611-622.
VÁCLAVÁ, ANTHONY Q. The variational Bayes method in signal processing[M]. Berlin, Germany: Springer, 2006:57-88.
NICOLAS F, LIAM O M, ERIC C.W32.stuxnet dossier [EB/OL]. [2010-9-30]. http:∥www.symantec. com/connect/blogs/w32stuxnet-dossier.html.
ALEKSANDR M, EUGENE R, DAVID H, et al. Stuxnet under the microscope [EB/OL]. [2010-7-19]. http:∥www. eset.com/resources/white-papers/Stuxnet_Under_the_Microscope.pdf.
0
浏览量
4
下载量
11
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621