西安交通大学智能网络与网络安全教育部重点实验室,西安,710049
网络首发:2012-06-10,
纸质出版:2012
移动端阅览
杨柳静, 秦涛, 王晨旭. 应用交互式网络流模型的高速网络异常行为检测与控制方法[J]. 西安交通大学学报, 2012,46(6):58-65.
Abnormal Behavior Detection and Control in High Speed Networks Based on Bidirectional Flow[J]. 2012, 46(6): 58-65.
针对网络异常流量的检测与定位问题
提出了一种根据网络流统计量异常变化和不完整网络流来有效识别并定位网络异常流量的方法.该方法建立在交互式网络流模型的基础上
分析了交互式网络流模型下各种网络流的交互特征; 为准确实时获取网络异常源
采用中国余数定理
设计了连接度sketch结构中的哈希函数
满足了网络用户信息逆向求解的需要
实现了高速网络中异常网络流特征参数的实时获取; 为减缓网络异常行为的扩散速度
提出采用动态软隔离方法实现网络异常行为的控制.真实环境下的实验结果表明
所提方法对于多种类型的网络异常行为具有良好的检测效果
检测的准确率和速率都得到了提高
同时可以准确地定位网络异常源
为有效控制网络异常行为的扩散奠定了基础.
A new method is proposed to effectively identify and locate the abnormal network flows based on the abnormal changes of the flow statistics and the incomplete flows. The method bases on the bidirectional flow model
and analyzes the interactive features of different network flows. A hash function in the structure of the connection degree sketch is designed by using the Chinese remainder theorem
so that the source of the abnormal behaviors can be accurately and timely achieved
and the users'information is obtained from the abnormal flows in the high-speed networks. The dynamic and soft isolation method is used to control the abnormal behaviors and hence to slow down the spread speed of the abnormal behaviors. The experimental results in an actual network show that the proposed method is efficient in improving both the detection accuracy and speed for most kinds of abnormal behaviors. At the same time
the source of the abnormal flow is exactly located
and it is helpful to control the spread of the abnormal behaviors.
MOORE D, SHANNON C. Code-red: a case study on the spread and victims of an internet worm[C]∥Proceedings of the 2002 ACM SICGOMM Internet Measurement Workshop. New York, NY, USA:ACM, 2002:273-284.
KIENZLE M, ELDER M. Recent worms: a survey and trends[C]∥Proceedings of the ACM CCS Workshop on Rapid Malicious Code. New York, NY, USA:ACM, 2003:1-10.
STANIFORD S, PAXSON V, WEAVER N, et al. How to own the internet in your spare time [C]∥Proceedings of the 11th USENIX Security Symposium. Berkeley, CA, USA: USENIX Association, 2002:149-167.
DOULIGERIS C, MITROKOTSA A. DDoS attacks and defense mechanism: classification and state of the art [J].Computer Networks, 2004, 44(4):643-666.
PENG Tao, LECKIE C, RAMAMOHANARAO K. Survey of network based defense mechanisms: countering the DoS and DDoS problems [J].ACM Computing Survey, 2007, 39(l): l-42.
肖志新,杨岳湘,杨霖.一个基于NetFlow的异常流量检测与防护系统[J].微电子学与计算机, 2006, 23(5):209-213.
XIAO Zhixin, YANG Yuexiang, YANG Lin. An anomaly traffic detection and network defending system based on NetFlow [J]. Microelectronics and Computer, 2006, 23(5):209-213.
KIM M S, KONG H J, HONG S C, et al. A flow-based method for abnormal network traffic detection [C]∥Proceedings of the Network Operations and Management Symposium. Piscataway, NJ, USA: IEEE, 2004:599-612.
KRISHNAMURTHY B, SEN S, ZHANG Yin, et al. Sketch-based change detection: methods, evaluation, and applications[C]∥Proceedings of the ACM SIGCOMM Internet Measurement Conference. New York, NY, USA:ACM, 2003:234-247.
GIBBONS P B, MATIAS Y. Synopsis structures for massive data sets[C]∥Proceedings of the 10th Annual ACMSIAM Symposium on Discrete Algorithms. Philadelphia, PA, USA: Society for Industrial and Applied Mathematics, 1999: 909-910.
MUTHUKRISHNAN S. Data streams: algorithms and applications [M].Boston, MA, USA: Now Publishers Inc., 2003.[11] 冯文峰,黄永峰,李星. 可逆概要数据结构[J].清华大学学报,2008,48(10):1625-1628.
FENG Wenfeng, HUANG Yongfeng, LI Xing. Reversible sketch data structure [J].Journal of Tsinghua University, 2008, 48(10):1625-1628.
SCHWELLER R, LI Zhichun, CHEN Yan, et al. Reversible sketches: enabling monitoring and analysis over high-speed data streams [J].Transactions on Networking, 2007, 15(5):1059-1072.
ZHAO Qi, KUMAR A, XU Jun. Joint data streaming and sampling techniques for detection of super sources and destinations[C]∥Proceedings of ACM SIGCOMM Internet Measurement Conference. New York, NY, USA: ACM, 2005:77-90.
GUAN Xiaohong, WANG Pinghui, QIN Tao. A new data streaming method for locating hosts with large connection Degree [C]∥Proceedings of IEEE Global Communications Conference. Piscataway, NJ, USA: IEEE, 2009:6421-6426.
STALLINGS W. Cryptography and network security: principles and practice [M].4th ed. Upper Saddle River, NJ,USA: Prentice-Hall, 1998.
ZOU C C, GONG Weibo, TOWSLEY D. Worm propagation modeling and analysis under dynamic quarantine defense.[C]∥Proceedings of ACM Workshop on Rapid Malcode. New York, NY, USA:ACM,2003: 51-60.
丁要军,蔡皖东.采用两阶段策略模型(KTSVM)的P2P流量识别方法. 2012,46(2):45-50.
侯重远,江汉红,芮万智,等. 工业网络流量异常检测的概率主成分分析法. 2012,46(2):70-75.
任浩,王劲林,尤佳莉.采用节点优先级的对等网络流媒体请求量分配算法. 2011,45(12):10-15.
褚伟波,蔡忠闽,管晓宏,等.采用子网流量组合优化的网络流量分割方法. 2011,45(12):22-27.
陈刚,蔡远利,穆静,等.海量信息异常检测问题的异常概率排序算法. 2011,45(4):36-40.
崔筱宁,赵保华,李青,等.传感器数据中事件样本与错误样本的系统化区分框架. 2010,44(10):30-35.
颜若愚,郑庆华.使用交叉熵检测和分类网络异常流量. 2010,44(6):10-15.
颜若愚,郑庆华,牛国林.自适应滤波实时网络流量异常检测方法. 2009,43(12):1-5.
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621