期刊文献+

基于HMM的分布式拒绝服务攻击检测方法 被引量:4

A DDoS Attack Detection Method Based on Hidden Markov Model
下载PDF
导出
摘要 文章根据分布式拒绝服务攻击(DDoS)的本质特点,提出了一种基于隐马尔可夫模型(HMM)的DDoS攻击检测方法。该方法通过IP地址信息库,保存当前常用服务的源IP地址,然后对新到数据包的IP地址用HMM建模。通过离线训练,更新IP地址信息库,优化HMM参数。在线检测时,IP地址信息库在线学习更新,HMM实时检测,并根据检测结果通过边界路由器进行积极响应。实验结果显示,该方法具有很好的检测效果,并能及时响应,保持常用服务的延续性。 On the basis of the inherent feature of distributed denial of service (DDoS) attacks, a novel approach of detection of DDoS attacks based on hidden Markov model (HMM) is proposed. We first build an IP addresses database, which keeps all the legitimate IP addresses which have previously appeared in the network, and then established HMM, which is based on the new IP addresses of normal network data packet. HMM and IP address database is trained separately though off-line training. The model is then used to detect the DDoS attacks by processing the network traffic and the edge router is used to decide whether to admit an incoming IP packet. Experimental results show that this method works very well on the DDoS attacks in adaptability and detection accuracy.
出处 《微电子学与计算机》 CSCD 北大核心 2006年第10期176-177,180,共3页 Microelectronics & Computer
基金 国家自然科学基金项目(60303012)
关键词 分布式拒绝服务 隐马尔可夫模型 学习机制 Distributed denial of service, Hidden Markov model, Learning mechanism
  • 相关文献

参考文献3

  • 1Ratul Mahajan,Steven M.Bellovin,Sally Floyd.et al.Controlling high bandwidth aggregates in the network.Technical report,AT&T Center for Internet Researeh at ICSI (ACIRI) and AT&T Labs Research,February 2001
  • 2Lawrence R Rabiner.A tutorial on hidden Markov models and selected applications in speech recognition.Proc.IEEE 1989,77(2):257~286
  • 3L R Rabiner,B H Juang.An introduction to hidden Markov models.IEEE ASSP Magazine.1986,3(1):4~16

同被引文献15

引证文献4

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部