
VTP检测算法的改进和基于模糊逻辑的DDoS攻击自适应判断 被引量:8

VTP detection algorithm improvement and the self-adaptability judgment of DDoS
摘要 传统DDoS判断方法主要是借助已知的Hurst值和经验进行人工判断,判断缺乏自适应性,且带有很大主观性。考虑到DDoS攻击是一个动态多变的过程,本文在研究DDoS攻击对网络流量自相似性影响的基础上,提出采用滑动窗口机制的方差时间图法估算Hurst值,实时检测DDoS攻击,结合实验数据,采用模糊逻辑技术设计了一个智能的DDoS判断机制,解决了该方法实现过程中参数选择、求解Hurst值等关键问题。通过DARPA1999年IDS基准评测数据的实验评测表明,新方法能够识别不同强度DDoS攻击引起的Hurst值的变化,实时检测DDoS攻击,增强了DDoS判断的灵活性,智能实现对DDoS攻击过程的在线实时自适应判断。 Traditional DDoS judgment mainly depends on the known Hurst parameter and experience to make artificial judgment. It lacks self-adaptability and has great subjectivity. Considering that DDoS attack is a process that changes dynamically and frequently, this paper first put forward a Variance-time plots method adapting slide-window mechanism to estimate Hurst parameter to detect DDoS attack in real time based on the study of how DDoS attack influence the self-similar traffic of network, then by adapting fuzzy logic technology, the paper designs a intelligent DDoS judgment mechanism, and thus solved many key problems in the implementation of the method such as the choosing of parameter, the solution of Hurst parameter. We apply the 1999 DARPA offline intrusion detection evaluation to carry out simulation. The experiment indicates that the new method can identify the change of Hurst parameter caused by different strength DDoS attack, can detect DDoS attack in re.al time, and can improve flexibility of DDoS attack judgment, thus achieve the goal of making on- line and real-time judgment of DDoS attack self-adaptively and intelligently.
作者 王江涛 杨庚
出处 《仪器仪表学报》 EI CAS CSCD 北大核心 2008年第2期342-348,共7页 Chinese Journal of Scientific Instrument
基金 江苏省自然科学基金(BK2004218) 江苏省“六大人才高峰”项目(06-E-044)资助
关键词 异常检测 分布式拒绝服务 自相似 实时检测 方差时间图 智能决策 abnormal detection distribute denial of service self-similarity real-time detection variance-time plots intelligent decision
  • 相关文献


  • 1PAXSON V, FLO Y D S. Wide area traffic: the failure of poisson modeling [ J ]. IEEE/ACM Trans. on Networking, 1995,3(3) :226-244.
  • 2LELAND W E, TAQQU M S, WILLINGER W, et al. On the self-similar nature of Ethernet traffic [ J ]. Extended version. IEEE/ACM Trans. on Networking, 1994,2 (1) :1-15.
  • 3SAHINOGLU Z, TEKINAY S. On multimedia networks: self-similar traffic and network performance [ J ]. IEEE Communications Magazine, 1999,37 ( 1 ) :48-52.
  • 4OZKURT T E, AKGUL T, BAYKUT S. Principal component analysis of the fractional brownian motion for 0 < H < 0.5 [ A ]. Acoustics, Speech and Signal Processing, 2006. ICASS P2006 Proceedings. 2006 IEEE International Conference[C]. Volume 3,21 -24 May 2006 Ⅲ: 488-491.
  • 5KIM Y G, SHIRAVI A, MIN PS. Congestion prediction of self-similar network through parameter estimation [ J ]. Network Operations and Management Symposium, 2006. NOMS 2006. 10th IEEE/IFIP. 2006: 1-4.
  • 6GUANGHUI H, HOU J C. An in-depth, analytical study of sampling techniques for self-similar Internet traffic [ A ]. Distributed Computing Systems, 2005. ICDCS 2005. Proceedings. 25th IEEE International Conference [C]. 06-10 June 2005:404-413.
  • 7XIANG Y, LIN Y, LEI W L, et al. Detecting DDoS attack based on network self-similarity [ J]. IEEE Int'l Conf. on Communications, 2004,151 (3) :292-295.
  • 8ZHANG H F, SHU Y T, YANG O. Estimation of Hurst parameter by variance-time plots [ J ]. Proceedings of the IEEE Pacrim 1997,2:883-886.
  • 9BODRUZZAMAN M, CADZOW J. Hurst's rescaled-range (R/S) analysis and fractal dimension of electromyographic (EMG) signal [ J ]. Proc. of IEEE Souteastcon' 91, Williamsburg, VA, April 1991:1121-1123.
  • 10POPESCU A. Traffic self-similarity[ A]. IEEE International Conference on Telecommunications, ICT2001 [ C ]. Bucharest, Romania, June 2001:20-24.











使用帮助 返回顶部