期刊文献+

基于IPFIX的大规模网络异常流量检测机制研究 被引量:4

IPFIX based large-scale network anomalous traffic flow detection
下载PDF
导出
摘要 对于大规模网络异常流量检测,由于数据包数量和规模过于庞大,利用传统的深度包检测技术难以在线实时发现网络中存在的攻击,尤其是网络中存在的新型的未知异常流量.本文利用分析IPFIX流量日志,对IPFIX流量进行属性提取,提出了一种改进K-means的算法,用于分析大规模高速网络中未知的异常流量,对于产生的聚类结果加以分析,得出网络中存在的新型的异常流量,并根据类内聚合程度,对类内发现的异常IP进行排查,从而判断攻击源. For the large scale network traffic anomaly detection, as the number of data packets and the scale is too large, packet detection technology is difficult to detect the network attacks with traditional method in real-time. Especially for the un- known abnormal traffic behavior is more difficult to detect. This paper utilize the analysis of IPFIX. After extracting the flow at- tribute, use improved K-means algorithm to analyze the abnormal flow in massive network. Abnormal traffic will be presented in the abnormal cluster with the value of polymerization degree. As the abnormal cluster^s polymerization degree is much more higher than the normal clusters', it can find the attack source in the cluster.
出处 《天津理工大学学报》 2015年第3期1-5,11,共6页 Journal of Tianjin University of Technology
基金 国家自然科学基金(61272450) 天津市科技计划项目(14ZCZDGX00072) 天津市物联网智能信息处理创新团队建设项目(TD12-5016)
关键词 异常流量 IPFIX 聚类 K—means abnormal traffic IPFIX clustering K-means
  • 相关文献

参考文献5

二级参考文献17

  • 1(美)SrinivasanS.高级Perl编程[S].北京:中国电力出版社,2001..
  • 2Estan C,Savage S,Varghese G Automatically Inferring Patterns of Resource Consumption in Network Traffic[C].In Proceeding of SIGCOMM,2003.
  • 3Cisco.NetFlow Services and Applications.White Paper,1999.
  • 4Jeffrey Dean, Sanjay Ghemanwat, MapReduce: Simplified Data Processing on Large Clusters.
  • 5Kenneth Heafield Hadoop Design and K-Means Clustering Google Inc January 15 2008.
  • 6Bradley, Fayyad, Refining Initial Points for K-Means Cluster- ing 1998.5.
  • 7Dummler, Rauber, Runger, Mapping Algorithms for Muhipro- cessor Tasks on Multi-core Clusters.
  • 8陈一骄,卢锡城,孙志刚.面向流管理的哈希算法研究[J].计算机工程与科学,2008,30(4):26-29. 被引量:11
  • 9李兴国,费玲玲.基于Netflow的流量分析技术研究[J].微计算机信息,2008,24(15):198-200. 被引量:14
  • 10强士卿,程光.基于流的哈希函数比较分析研究[J].南京师范大学学报(工程技术版),2008,8(4):25-28. 被引量:7

共引文献34

同被引文献38

引证文献4

二级引证文献24

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部