期刊文献+

基于ANN与KPCA的LDoS攻击检测方法 被引量:10

Detection method of LDoS attacks based on combination of ANN & KPCA
下载PDF
导出
摘要 低速率拒绝服务(LDoS,low-rate denial of service)攻击是一种新的面向TCP协议的攻击方式,它具有攻击速率低、隐蔽性强的特点,很难被传统DoS攻击检测措施发现。针对其特点,采用网络大数据分析技术,从路由器队列中挖掘一种LDoS攻击特征,将核主成分分析(KPCA,kernel principal component analysis)方法与神经网络结合,提出一种新的检测LDoS攻击的方法。该方法将路由器队列特征采用KPCA降维,作为神经网络输入,再利用BP神经网络自学习能力生成LDoS分类器,达到检测LDoS攻击的目的。实验结果表明该方法有较好的检测有效性和较低的计算复杂度,对设计防御LDoS攻击的路由器有一些借鉴意义。 Low-rate denial-of-service(LDoS) attack is a new type of attack mode for TCP protocol. Characteristics of low average rate and strong concealment make it difficult for detection by traditional Do S detecting methods. According to characteristics of LDoS attacks, a new LDoS queue future was proposed from the router queue, the kernel principal component analysis(KPCA) method was combined with neural network, and a new method was present to detect LDoS attacks. The method reduced the dimensionality of queue feature via KPCA algorithm and made the reduced dimension data as the inputs of neural network. For the good sell-learning ability, BP neural network could generate a great LDoS attack classifier and this classifier was used to detect the attack. Experiment results show that the proposed approach has the characteristics of effectiveness and low algorithm complexity, which helps the design of high performance router.
作者 吴志军 刘亮 岳猛 WU Zhijun;LIU Liang;YUE Meng(School of Electronics Information & Automation, Civil Aviation University of China,Tianjin 300300, Chin)
出处 《通信学报》 EI CSCD 北大核心 2018年第5期11-22,共12页 Journal on Communications
基金 国家自然基金委员会与中国民航局联合基金资助项目(No.U1533107) 天津市自然科学基金资助项目(No.17JCZDJC30900)~~
关键词 低速率拒绝服务攻击 队列特征 核的主成分分析 神经网络 low-rate denial of service queue feature kernel principal component analysis neural network
  • 相关文献

参考文献10

二级参考文献119

  • 1卢锡城,张明杰,朱培栋.自适应PI主动队列管理算法[J].软件学报,2005,16(5):903-910. 被引量:19
  • 2纪其进,董永强.一种链路负载自适应的主动队列管理算法[J].软件学报,2006,17(5):1140-1148. 被引量:7
  • 3杨吉文,顾诞英,张卫东.主动队列管理中PID控制器的解析设计方法[J].软件学报,2006,17(9):1989-1995. 被引量:5
  • 4彭丽芳,孟志青,姜华,田密.基于时间序列的支持向量机在股票预测中的应用[J].计算技术与自动化,2006,25(3):88-91. 被引量:31
  • 5Kuzmanovic A, Knightly EW. Low-Rate TCP-targeted denial of service attacks--the shrew vs. the mice and elephants. In: Proc. of the ACM SIGCOMM 2003. New York: ACM Press, 2003. 75-86. http://byte.csc.lsu.edu/-durresi/7502/reading/p75-kuzmanovic. pdf.
  • 6Sarat S, Terzis A. On the effect of router buffer sizes on low-rate denial of service attacks. In: Proc. of the 14th Int'l Conf. on Computer Communications and Networks (ICCCN 2005). New York: IEEE Press, 200S. 281-286. http://www.cs.jhu.edu/-sarat/ ICCCN05.pdf.
  • 7Kwok YK, Tripathi R, Chen Y, Hwang K. HAWK: Halting anomalies with weighted choking to rescue well-behaved TCP sessions from shrew DDoS attacks. In: Proc. of the 3rd Int'l Conf. on Networking and Mobile Computing (ICCNMC 2005). New York: Springer-Verlag, 2005.423-432. http://gridsec.usc.edu/files/TR/HAWK-ICCNMC2005-CameraReady.pdf.
  • 8Sun H, Lui JCS, Yau DKY. Defending against low-rate TCP attacks: Dynamic detection and protection. In: Proc. of the 12th IEEE Int'l Conf. on Network Protocols (ICNP 2004). New York: IEEE Press, 2004. 196-205. http://www.cse.cuhk.edu.hk/-cslui/ PUBLICATION/icnp_lowrate.pdf.
  • 9Sun H, Lui JCS, Yau DKY. Distributed mechanism in detecting and defending against the low-rate TCP attack. Computer Networks, 2006,50(13):2312-2330.
  • 10Chen Y, Hwang K. Collaborative detection and filtering of shrew DDoS attacks using spectral analysis. Journal of Parallel and Distributed Computing, 2006,66(9): 1137-1151.

共引文献103

同被引文献73

引证文献10

二级引证文献13

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部