期刊文献+

基于IP地址聚类的网络异常流量分析

Abnormal Network Traffic Analysis Based on IP Address Clustering
下载PDF
导出
摘要 异常流量在目的地址与出现时间上的分布均与正常流量有很大区别。文中对校园网的出口流量进行分析实验,将其NetFlow记录按校外IP地址的前16位聚类,得到的部分网段在出入流量中的出现频度有明显特点。分析2种典型网段,研究由此发现校园网内的异常流量源的方法,并对2种异常流量源的区别进行了分析。此方法与常用的异常检测方法相比,所需处理的数据量大为减少,大大提高了检测效率。 Abnormal traffic appears very different from normal traffic on the distribution of both destination IP address and time.This paper clusters the Netflow records of the traffic via the campus network based on the higher 16 bits of the outer IP address,finding that some clusters appear unusual on frequency of the emergence.This paper analyzes two kinds of typical cluster,proposes a method to detect anomaly sources insides the campus network using the clusters,and finds the differences of two kinds of anomaly s...
出处 《中国海洋大学学报(自然科学版)》 CAS CSCD 北大核心 2008年第S1期187-190,共4页 Periodical of Ocean University of China
关键词 NETFLOW 异常检测 流量分析 NetFlow anomaly detection network traffic analysis
  • 相关文献

参考文献2

二级参考文献11

  • 1(美)SrinivasanS.高级Perl编程[S].北京:中国电力出版社,2001..
  • 2Estan C,Savage S,Varghese G Automatically Inferring Patterns of Resource Consumption in Network Traffic[C].In Proceeding of SIGCOMM,2003.
  • 3Cisco.NetFlow Services and Applications.White Paper,1999.
  • 4D.E.Denning.An Intrusion Detection Model.IEEE Transactions on Software Engineering,February 1987.
  • 5FAQ:Network Intrusion Detection Systems.Version 0.8.3 March 21,2000 http://www.robertgraham.com/pubs/network-intrusion-detection.html
  • 6Cisco.NetFlow Services Solution Guide 2001.
  • 7Cisco.NetFlow Performance Analysis White Paper.
  • 8Yiming Gong.Detecting Worms and Abnormal Activities with NetFlow http://www.securityfocus.com/infocus/1796.August 16,2004.
  • 9Snort,The Open Source Network Intrusion Detection System.http://www.snort.org
  • 10许榕生,钱桂琼,杨泽明.宽带网下入侵检测系统的研究与探讨[J].计算机工程与应用,2002,38(10):149-151. 被引量:8

共引文献32

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部