1. 西安交通大学电子与信息工程学院,西安,710049
2. 广东海洋大学信息学院,广东,湛江,524088
网络首发:2009-12-10,
纸质出版:2009
移动端阅览
颜若愚 1, 2, 郑庆华 1, 等. 自适应滤波实时网络流量异常检测方法[J]. 西安交通大学学报, 2009,43(12):1-5.
On-Line Anomaly Detection Method for Network Traffic Based on Adaptive Filtering[J]. 2009, 43(12): 1-5.
针对网络中的各种常见攻击
提出一种基于自适应滤波的网络流量异常检测方法.首先对多种流量指标进行递推最小二乘法预测
然后以预测误差所构造的统计量容许范围进行异常检测
最后对检测结果实施归一化评估.该方法具有无需任何历史训练数据、能大量减少报警次数、突出报警严重程度的特点.在DARPA入侵检测评估数据集上的实验表明
所提方法更适合检测拒绝服务攻击引起的异常
较之相同权向量下的同类方法
其异常检测率、误报率和检测速度等性能更好.
A network traffic anomaly detection method based on adaptive filter is proposed to detect all kinds of network traffic attacks. Multiple network traffic indicators are predicted by recursive least square and the allowable statistical range based on the prediction errors are used to detect anomaly. Detection results are finally normalized. The method has the following traits: no training from any historical data
reducing the number of alarms
remarkably
and highlighting the severity of alarms. Testing results on DARPA intrusion detection data sets show that the proposed method is more suitable to detect denial of service attacks
and has a higher detection rate
faster speed and lower alarm rate than similar existing methods with same dimension of weight vectors.
姚婷婷, 郑庆华, 管晓宏, 等. 一种基于主机实时流量的安全评估方法[J].西安交通大学学报,2006,40(4):415-419.
YAO Tingting, ZHENG Qinghua, GUAN Xiaohong,et al. Security evaluation method based on real time traffic of hosts [J]. Journal of Xi'an Jiaotong University, 2006, 40(4): 415-419.
邹柏贤. 一种网络异常实时检测方法[J]. 计算机学报, 2003, 26(8): 940-947.
ZOU Boxian. A real-time detection method for network traffic anomalies [J]. Chinese Journal of Computers, 2003, 26(8): 940-947.
曹晓梅,韩志杰,陈贵海.基于流量预测的传感器网络拒绝服务攻击检测方案[J]. 计算机学报, 2007, 30(10): 1798-1805.
CAO Xiaomei,HAN Zhijie, CHEN Guihai. DoS attack detection scheme for sensor networks based on traffic prediction [J]. Chinese Journal of Computers, 2007, 30(10): 1798-1805.
ZARE M H, MASNADI-SHIRAZI M A. Arima model for network traffic prediction and anomaly detection[C]∥Proceedings of ITSim International Symposium on Information Technology. Piscataway, NJ, USA: IEEE, 2008:1-6.
VOELKER M D, SAVAGE S G M. Inferring internet denial-of-service activity [C]∥Proceeding of the 10th USENIX Security Symposium. Berkeley, CA, USA: The Advanced Computing Systems Association, 2001:9-22.
Massachusetts Institute of Technology. Lincoln. Laboratory. DARPA intrusion detection evaluation[EB/OL].(2008-06-01)[2009-03-02]. http:∥www.ll.mit.edu/IST/ideval/data/data-index.html.
AUGUSTIN S, KAVE S, NINA T. Combining filtering and statistical methods for anomaly detection [C]∥Prceedings of USENIX Association Internet Measurement Conference. Berkeley, CA, USA: The Advanced Computing Systems Association, 2005:331-344.
0
浏览量
4
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621