期刊文献+

一种新的可变采样率的网络流量抽样测量方法 被引量:3

IP flow-based variable sampling method for network traffic measurement
下载PDF
导出
摘要 随机报文抽样方法是目前常用的流量抽样测量方法,但是它倾向于采集长流,影响了异常检测的正确性.提出了一种新的基于IP流可变采样率的网络流量抽样测量方法,将到达的数据报文按照流标识分类,并以每一个报文在所属流中的位置和流的大小为参数设置可变采样率进行抽样测量.实验表明,该方法提高了短流中报文的采样率,减少了随机报文抽样方法对异常检测的影响,检测结果能正确地反映原始数据的异常情况. The random packet sampling method is usually employed by traffic sampling measurement. But the accuracy of anomaly detection is affected by the fact that it biases a large IP flow. Based on the IP flow arrival process, a variable sampling method is proposed. According to the attribute of the IP flow, the incoming packets are classified by their flow identifiers and sampling rates are set by their positions in the IP flow. Experimental results show that sampled traffic data improve the accuracy of anomaly detection because the variable sampling method increases the sampling rate of packets in a small IP flow.
作者 潘乔 裴昌幸
出处 《西安电子科技大学学报》 EI CAS CSCD 北大核心 2008年第6期968-972,共5页 Journal of Xidian University
基金 国家自然科学基金资助(60572147,60132030)
关键词 抽样测量 可变采样率抽样 IP流 端口扫描 INTERNET sampling measurement variable sampling IP flow port scan
  • 相关文献

参考文献10

  • 1Liu Y, Towsley D,Ye T, et al. An Information-theoretic Approach to Network Monitoring and Measurement [C]//Proc of ACM Conference on Internet Measurement. Berkeley: ACM, 2005: 159-172.
  • 2Paul B, Jeffery K, David P, et al. A Signal Analysis of Network Traffic Anomalies [C]//Proc of ACM SIGCOMM Workshop on Internet Measurement. Marseilles: ACM, 2002: 71-82.
  • 3Avinash S, Tao Y, Supratik B. Connectionless Port Scan Detection on the Backbone [C]//Proc ot lnternet Pertormance, Computing, and Communications Conference. Phoenix: IEEE, 2006: 567-576.
  • 4Avinash S, Tao Y, Supratik B. Connectionless Port Scan Detection on the Backbone [C]//Proc of Internet Performance, Computing, and Communications Conference. Phoenix: IEEE, 2006: 567-576.
  • 5Jianning M, Chuah C N, Ashwin S, et al. ls Sampled Data Sufficient for Anomaly Detection[C]//Proc of ACM SIGCOMM Conference on Internet Measurement. Rio de Janeriro: ACM, 2006.. 165-176.
  • 6Cisco Systems, Inc. Random Sampled NetFlow[OL]. [2007-08-27]. http://www, cisco, eom/en/US/products/ps6566/ products_ feature guide09186a0080796a49, html.
  • 7Claise B. Specification of the IPFIX Protocol for the Exchange of IP Traffic Flow Information [OL]. [2008-01-01]. http://tods, ietf. org/htm, rfc5101.
  • 8Duffield N, Lund C, Thorup M. Estimating Flow Distributions from Sampled Flow Statistics[J]. IEEE/ACM Trans on Networking, 2005, 13(5): 933-946.
  • 9ApisdorI J, Claffy K, Thompson K, et al. OC3MON: Flexible, Affordable, High Performance Statistics Collection [C]//Proc of Internet Society's 7th Annual Conference. Kuala Lumpur: Internet Society, 1997: 97-112.
  • 10Staniford J, Hoagland A, McAlemy J M. Practical Automated Detection of Stealthy Portscans[J]. Journal of Computer Security, 2002, 10(2): 105-136.

同被引文献27

  • 1周明中,龚俭,丁伟.高速网络中基于流速测度的动态超时策略[J].软件学报,2006,17(10):2141-2151. 被引量:5
  • 2第27次中国互联网络发展状况统计报告[EB/OL].http://tech.sina.com.cn/z/cnnic27/.2011-01-18.
  • 3王丹,谢高岗,杨建华,张广兴,李振宇.一种改进的自适应流量采样方法[J].计算机研究与发展,2007,44(8):1339-1347. 被引量:7
  • 4Paul B,Jeffery K,David P,et al.A Signal Analysis of NetworkTraffic Anomalies[C]//Proceedings of ACM SIGCOMM InternetMeasurement Workshop.New York,USA:ACM Press,2002.
  • 5Addie R G,Neame T D,Zukerman M.Performance Evaluation ofa Queue Fed by a Poisson Pareto Burst Process[J].ComputerNetworks,2009,53(7):1099-1134.
  • 6张兴明.大规模接入汇聚路由器(ACR)总体技术规范[Z].国家数字交换系统工程技术研究中心,2005.
  • 7陈伟,周继军,许德武.入侵检测系统全攻略[M].北京:北京邮电大学出版社,2009.
  • 8Abilene-I[EB/OL].[2010-12-12].http://pma.nlanr.net/traces/long/ipls1.html.
  • 9Dataset for“DDoS Attack 2007”[EB/OL].[2010-11-12].http://www.caida.org/data/.
  • 10Mai J,Chuah C N,Sridharan A,et al.Is sampled data sufficient for anomaly detection?[C]//Proc of the 6th ACM SIGCOMM Conference on Internet Measurement.New York:ACM Press,2006:165-176.

引证文献3

二级引证文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部