1. 西安交通大学电子与信息工程学院,西安,710049
2. 西安交通大学智能网络与网络安全教育部重点实验室,西安,710049
3. 陕西省天地网技术重点实验室,西安,710049
网络首发:2008-08-10,
纸质出版:2008
移动端阅览
王志文 1, 2, 3, 等. 一种面向网络行为因果关联的攻击检测方法[J]. 西安交通大学学报, 2008,42(8):931-935.
王志文 1, 2, 3, et al. Approach for Detecting Attack Based on Causality of Network Behavior[J]. 2008, 42(8): 931-935.
为了能在攻击目标受损之前检测到攻击事件
提出了面向网络行为因果关联的攻击检测方法.该方法基于SNMP管理信息库数据
根据攻击目标的异常行为
首先利用Granger因果关联检验(GCT)从检测变量中挖掘出与异常变量存在整体行为关联的基本攻击变量
然后针对异常行为特征再次利用GCT从基本攻击变量中挖掘出与异常变量存在局部行为关联的攻击变量
最后根据攻击变量和异常变量之间的因果关系
构建面向攻击方检测的攻击关联规则.在Trin00 UDP Flood检测实验中
所提方法成功挖掘出攻击变量udpOutDatagram
取得了满意的检测效果.实验结果表明
该方法能够在攻击方检测到攻击事件
为及时阻止攻击过程向攻击目标进一步扩散提供预警.
An SNMP MIB oriented approach based on causality in network behavior is presented in order to detect attack before the security of target is damaged. According to the behavior of an abnormal variable in target
Granger causality test(GCT)is used to find preliminary attacking variables which are causality relevant to the abnormal variable in whole network behavior. Depending on the behavior features hidden in the abnormal behavior
GCT is used again to recognize attacking variables which are causality relevant to the abnormal variable in local network behavior. The causality between attacking variables and the abnormal variable is then used to construct detecting rules
which are oriented to attacker. udpOutDatagrams acting as attacking variable are recognized successfully and detection results are acquired well in the test of Trin00 UDP Flood. The experiment results show that the approach can effectively detect attacks from attackers
which has effect on blocking the pervasion of attacking procedure to target.
THOTTAN M, JI Chuanyi. Anomaly detection in IP networks[J]. IEEE Trans on Signal Processing, 2003,51(8):2191-2204.
CABRERA J B D, LEWIS L, QIN Xinzhou. Proactive detection of distributed denial of service attacks using MIB traffic variables:a feasibility study [J]. IEEE Trans on Signal Processing, 2001,49(6):609-622.
汪生,孙乐昌,干国政. Granger因果关系检验在攻击检测中的应用研究 [J]. 计算机应用, 2005,25(6):1282-1285.
WANG Sheng, SUN Lechang, GAN Guozheng. Application research based on Granger causality test for attack detection [J]. Computer Applications, 2005, 25(6):1282-1285.
邹柏贤,姚志强. 一种网络流量平稳化方法 [J]. 通信学报, 2004,25(8):14-23.
ZOU Baixian, YAO Zhiqiang. A method to stabilize network traffic [J]. Journal of China Institute of Communications, 2004,25(8):14-23.
HAMILTON J. Time series analysis [M]. Princeton, NJ, USA: Princeton University Press, 1994.
CRISCUOLO P J. Distribution denial of service: trin00, tribe flood network, gribe flood network 2000, and stacheldraht, CIAC-2319 [R]. Washington DC,USA: Computer Incident Advisory Capacity, Department of Energy, 2000.
0
浏览量
5
下载量
1
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621