期刊文献+

基于行为模型的IP Forwarding异常检测方法 被引量:1

Anomalies detection method of IP forwarding based on behavior model
下载PDF
导出
摘要 通过研究网络流动态特征,基于路由变化、流变化和包延迟,以及IP报文头信息(例如TTL、源/目的地址、报文长度和路由器时间戳)建立网络行为模型,通过高性能测量和在线分析网络流和路由信息对初始网络异常产生实时报警,实现了IP forwarding网络异常的有效检测和识别。定义了网络行为模型的五种功能模块,通过关联空间和时间状态信息检测识别网络异常为大范围监测网络提供强大支持。 A simple, robust method was proposed that integrated routing and traffic data streams to reliably detect forwarding anomalies. High resolution measurements and on-line analysis of network traffic and routing were used to provide real-time alarms in the incipient phase of network anomalies. The anomalies identification method based on behavior model used path changes, flow shift and packet delay variance and relied extensively on IP packet header information, such a~ TI'L, source/destination address, packet length, and routcr's timestamps. The overall method is scalable, automatic and selftraining, and effectively identifies forwarding anomalies, while avoiding the high false alarms rate.
出处 《计算机应用》 CSCD 北大核心 2006年第3期564-566,共3页 journal of Computer Applications
基金 国家自然科学基金资助项目(60273070 60473031)
关键词 行为模型 IP forwarding异常 生存时间(TTL) 路由 报文延迟 behavior model IP forwarding anomalies time to live(TTL) traffic route packet delay variance
  • 相关文献

参考文献6

  • 1OPPENHEIMER D,GANAPATHI A,PATTERSON DA.Why doInternet services fail,and what can be done about it?[A] 4th Usenix Symposium on Internet Technologies and Systems (USITS'03)[C],2003.
  • 2STEINER SH.Grouped data exponentially weighted moving average control charts[J].Applied Statistics,1998,47(2).
  • 3BRUTAG JD.Aberrant behavior detection and control in time series for network monitoring[A].Proceedings of the 14th Systems Administration Conference[C].LISA,2000.
  • 4BARFORD P,KLINE J,PLONKA D,et al.A signal analysis of network traffic anomalies[A].Proceedings of ACM SIGCOMM Internet Measurement Workshop[C].Marseilles,France,2002.
  • 5KRISHNAMURTHY B,SEN S,ZHANG Y,et al.Sketch-based change detection:Methods,evaluation,and applications[A].Internet Measurement Conference [C],2003.
  • 6ROUGHAN M,GREEBERG A,KALMANEK C,et al.Experience in measuring Internet backbone traffic variability:Models,metrics,measurements and meaning[A].Proceedings of the International Teletraffic Congress (ITC-18) [C],2003.

同被引文献4

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部