期刊文献+

基于小波能谱熵和隐半马尔可夫模型的LDoS攻击检测 被引量:11

Detection of LDoS Attacks Based on Wavelet Energy Entropy and Hidden Semi-Markov Models
下载PDF
导出
摘要 低速率拒绝服务(low-rate denial of service,简称LDoS)攻击采用周期性发送短脉冲数据包的方式攻击云计算平台和大数据中心,导致连接用户的路由器丢包和数据链路传输性能下降.LDoS攻击流量平均速率很低,具有极强的隐蔽性,很难被检测到.在分析LDoS攻击流量的基础上,通过小波变换得到网络流量的小波能谱熵,并以此作为隐半马尔可夫模型(HSMM)的输入,设计采用HSMM网络模型的LDoS攻击判决分类器,提出了基于小波能谱熵和隐半马尔可夫模型的LDoS攻击检测方法.该检测方法在NS-2和Test-bed环境中分别进行了测试.实验结果表明,该方法具有较好的检测性能,通过假设检验得出检测率为96.81%. Low-rate denial of service(LDoS) attack can cause the packets loss of the legitimate users and reduce the transmission performance of the transport system by sending short bursts of packets periodically. The LDoS attack flows always mix with the legitimate traffic, hence, it is hard to be detected. This study designs an LDoS attack classifier based on network model, which uses hidden semi-Markov model(HSMM), and deploys a decision indicator to detect LDoS attacks. In this method, wavelet transform is exploited to compute the network traffic’s wavelet energy spectrum entropy, which is used as the input of the HSMM. The proposed detection method has been evaluated in NS-2 and Test-bed, and experimental results show that it achieves a better performance with detection rate of 96.81%.
作者 吴志军 李红军 刘亮 张景安 岳猛 雷缙 WU Zhi-Jun;LI Hong-JUN;LIU Liang;ZHANG Jing-An;YUE Meng;LEI Jin(College of Electronic Information and Automation,Civil Aviation University of China,Tianjin 300300,China)
出处 《软件学报》 EI CSCD 北大核心 2020年第5期1549-1562,共14页 Journal of Software
基金 国家自然科学基金委员会与中国民航局联合基金(U1933108) 天津市教委科研项目(2019KJ117)。
关键词 低速率拒绝服务 网络测量 小波分析 隐半马尔可夫模型 异常检测 low-rate denial of service network measurement wavelet analysis hidden semi-Markov model anomaly detection
  • 相关文献

参考文献10

二级参考文献108

  • 1印欣运,何永勇,彭志科,褚福磊.小波熵及其在状态趋势分析中的应用[J].振动工程学报,2004,17(2):165-169. 被引量:49
  • 2桂中华,韩凤琴.小波包特征熵神经网络在尾水管故障诊断中的应用[J].中国电机工程学报,2005,25(4):99-102. 被引量:59
  • 3何正友,蔡玉梅,钱清泉.小波熵理论及其在电力系统故障检测中的应用研究[J].中国电机工程学报,2005,25(5):38-43. 被引量:188
  • 4Kuzmanovic A, Knightly EW. Low-Rate TCP-targeted denial of service attacks--the shrew vs. the mice and elephants. In: Proc. of the ACM SIGCOMM 2003. New York: ACM Press, 2003. 75-86. http://byte.csc.lsu.edu/-durresi/7502/reading/p75-kuzmanovic. pdf.
  • 5Sarat S, Terzis A. On the effect of router buffer sizes on low-rate denial of service attacks. In: Proc. of the 14th Int'l Conf. on Computer Communications and Networks (ICCCN 2005). New York: IEEE Press, 200S. 281-286. http://www.cs.jhu.edu/-sarat/ ICCCN05.pdf.
  • 6Kwok YK, Tripathi R, Chen Y, Hwang K. HAWK: Halting anomalies with weighted choking to rescue well-behaved TCP sessions from shrew DDoS attacks. In: Proc. of the 3rd Int'l Conf. on Networking and Mobile Computing (ICCNMC 2005). New York: Springer-Verlag, 2005.423-432. http://gridsec.usc.edu/files/TR/HAWK-ICCNMC2005-CameraReady.pdf.
  • 7Sun H, Lui JCS, Yau DKY. Defending against low-rate TCP attacks: Dynamic detection and protection. In: Proc. of the 12th IEEE Int'l Conf. on Network Protocols (ICNP 2004). New York: IEEE Press, 2004. 196-205. http://www.cse.cuhk.edu.hk/-cslui/ PUBLICATION/icnp_lowrate.pdf.
  • 8Sun H, Lui JCS, Yau DKY. Distributed mechanism in detecting and defending against the low-rate TCP attack. Computer Networks, 2006,50(13):2312-2330.
  • 9Chen Y, Hwang K. Collaborative detection and filtering of shrew DDoS attacks using spectral analysis. Journal of Parallel and Distributed Computing, 2006,66(9): 1137-1151.
  • 10Guirguis M, Bestavros A, Matta I. Exploiting the transients of adaptation for RoQ attacks on Internet resources. In: Proc. of the 12th IEEE Int'l Conf. on Network Protocols (ICN-P 2004). New York: IEEE Press, 2004. 184-195. http://www.ieee-icnp.org/ 2004/papers/5-2.pdf.

共引文献76

同被引文献137

引证文献11

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部