期刊文献+

基于小波的异常检测方法研究 被引量:1

Anomaly detection method based on wavelet
下载PDF
导出
摘要 针对DDoS攻击引起的网络异常,提出基于小波变换的检测方法.将网络流量分解到不同的频段,根据高频段频谱能量,即小波方差的变化对网络流量异常进行检测.为提高预警的准确性,吸取了路由器的设计思想,用LRU Cache滤掉长时流发现突发流量,实验证明本尝试是有效的. The distributed denial-of-service (DDoS) leading to network traffic anomaly is growing rapidly. In this paper, a network traffic anomaly detection method based on wavelet transform is proposed. Network traffic is broken down into different frequency, and anomaly change of network traffic is detected through the high-frequency power analysis, that is the change of wavelet variance. In order to enhance the alarm veracity, a LRU Cache is used to filter the long-term flow and part of outburst flow is found. Experiments proved that it is viable attempt to analyze network traffic from the aspect of frequency.
出处 《哈尔滨商业大学学报(自然科学版)》 CAS 2006年第6期58-61,共4页 Journal of Harbin University of Commerce:Natural Sciences Edition
基金 国家高技术研究发展计划(863计划)(2002AA142020)
关键词 异常检测 DDOS攻击 小波分析 LRU缓存 anomaly detection DDoS attacks wavelet analysis LRU Cache
  • 相关文献

参考文献12

  • 1FUCHS E,JACKSON P E.Estimates of Distributions of Random Variables for Certain Computer Communication Traffic Models[J].Comm.of ACM,1970,13(12):752-767.
  • 2HABRA N,BAUDOUIN L C,MOUNJI A,et al.ASZX:Software Architecture and Rule-Based Language for Universal Audit Trail Analysis[C] // Procedings of ESOPICS 92.1992,11Spring-Verlag:133-140.
  • 3LELAND W E,TAQQU M S,WILLINGER W,et al.On the Self-Similar Nature of Ethernet Traffic[J].IEEE/ACM Transactions on Networking,1994,2(1):1-15.
  • 4KLIVANSKY S K,MUKHERJEE.On Long Range Dependence in NSFNET Traffic[R].Technical Report GIT-CC-94/61,Geogia Institute of Technology,Altlanta,GA 30332,USA,1994.12.
  • 5JAIN R.ATM Networking:Issues and Challenges Ahead[C] //Networld + InterOp95 Engineer Conference,Las Vegas,Nevada,1995.27 -31.
  • 6TUAN T,PARK K.Multiple Time Scale Redundancy Control for QoS-sensitive Transport of Real-time Traffic[C]// Proc.IEEE INFOCOM00,2000.
  • 7ABRY P,VEITCH D.Wavelet Analysis of Long-range-dependent Traffic[C]// IEEE Trans.on Information Theory,1998,44(1):2-15.
  • 8FELDMANN A,GILBERT A C,Huang P,et al.Dynamics of IP Traffic:A Study of the Role of Variability and the Impact of Control[C]//Proceedings of the ACM/SIGCOMM 99,Cambridge,MA,1999.
  • 9PARTRIDGE C.The End of Simple Traffic Models[J].(Editor's Note),IEEE Network,1993,7(5):3 -3.
  • 10SHRIRAM S,RUDOLF R,RICHARD B.Connection-level analysis and modeling of network traffic[C]// Proc.of the ACM SIGCOMM Internet Messurement Workshop,San Francisco,CA,2001.99-103.

二级参考文献3

  • 1龙瑞麟.多元小波分析[M].北京:世界图书出版公司,1995.
  • 2ZHANG Q,BENVENISTE A.Wavelet Networks.IEEE Trans[J].on Neural Networks,1992,3(6):889-898.
  • 3KUGARJAH T,ZHANG Q.Multidimensional Wavelet Frames[J].IEEE Trans.on Neural Networks,1995,6(6):1552-1556.

同被引文献19

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部