1. 西安交通大学电子与信息工程学院,西安,710049
2. 广东海洋大学信息学院,广东,湛江,524088
网络首发:2010-06-10,
纸质出版:2010
移动端阅览
颜若愚 1, 2, 郑庆华 1. 使用交叉熵检测和分类网络异常流量[J]. 西安交通大学学报, 2010,44(6):10-15.
Using Cross Entropy to Detect and Classify Network Anomalous Traffic[J]. 2010, 44(6): 10-15.
针对准确识别网络攻击行为的问题
提出了一种基于交叉熵的流量异常检测和分类方法.首先使用流头部特征属性和行为特征属性对DoS攻击、端口扫描和网络扫描等3种常见攻击进行描述
并使用交叉熵来度量各属性上流量的分布变化
建立各攻击的行为特征向量
然后使用指数加权滑动平均控制图方法对多种交叉熵指标进行异常检测得到检测异常向量
最后以检测异常向量和各行为特征向量的相似度来判别攻击类型.针对路由器中Netflow流量的实验结果表明
对于强度较小的攻击
相比香农熵度量法
交叉熵度量法的攻击分类正判率和精确率平均提高了13%和15%
正确率提高了13%.
A traffic anomaly detection and classification method based on cross entropy is proposed to identify network attack behaviors accurately. Both features of traffic flow header and traffic behavior are used to characterize three types of common attacks
such as DoS attacks
port scans and network scans. The cross entropy is used to measure traffic distribution changes for each traffic feature
and a behavior vector for each attack type is built. Then exponentially weighted moving average control chart method is applied to multiple cross entropy indicators for anomaly detection
and an anomaly vector is generated. The similarity between the anomaly vector and each behavior vector is computed to classify attacks. Experimental results and comparisons with the Shannon entropy measurement on Netflow traffic in a router show that under relatively weaker attacks
the true positive rate
average precision and accuracy of the cross entropy measurement in attack classification rise by 13%
15%
and 13%
respectively.
陈光英,张千里,李星. 基于SVM分类机的入侵检测系统[J]. 通信学报, 2002, 23(5): 51-56.
CHEN Guangying, ZHANG Qianli, LI Xing. SVM classification-based intrusion detection system[J]. Journal of China Institute of Communications, 2002, 23(5): 51-56.
KRISHAN K, JOSHIL R C, KULDIP S. A distributed approach using entropy to detect DDoS attacks in ISP domain [C]∥Proceedings of International Conference on Signal Processing, Communications and Networking. Piscataway, NJ, USA: IEEE, 2007:331-337.
ANUKOOL L, MARK C, CHRISTOPHE D. Mining Anomalies using traffic feature distributions [C]∥Proceedings of Special Interest Group on Data Communication Conference. New York,USA: ACM, 2005:217-228.
GEORGE N, VYAS S, DAVID G, et al. An empirical evaluation of entropy-based traffic anomaly detection [C]∥Proceedings of Internet Measurement Conference. New York, USA: ACM, 2008:151-156.
QIN Tao, GUAN Xiaohong, LI Wei, et al. Dynamic features measurement and analysis for large-scale networks [C]∥Proceedings of International Conference on Communications. Piscataway, NJ, USA: IEEE, 2008: 212-216.
YAN Ruoyu, ZHENG Qinhua. Using renyi cross entropy to analyze traffic matrix and detect DDoS attacks [J]. Information Technology Journal, 2009, 8(8):1180-1188.
MONTGOMERY D C, MASTRANGELO C M. Some statistical process control methods for autocorrelated data [J]. Journal of Quality Technology, 1991, 23(3): 179-193.
0
浏览量
4
下载量
7
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621