期刊文献+

基于组合相关度的随机森林DDoS攻击检测方法 被引量:5

DDoS Attack Detection Method Based on Combination Correlation Degree and Random Forest
下载PDF
导出
摘要 提出了一种基于组合相关度的随机森林(random forest,RF) DDoS攻击检测方法.根据攻击流的非对称性和半交互性定义网络流组合相关度(combination correlation degree,CCD),该相关度以地址相关统计(address correla-tion statistics,ACS)特征以及单向流半交互度(unidirectional flow semi interaction,UFSI)二元组来描述网络流的特点.然后提出基于CCD特征序列的遗传算法对RF中决策树的最大数量和最大深度两个关键参数进行优化,对参数优化的RF模型进行训练以生成分类模型来检测攻击.实验结果表明,与同类方法相比,该方法具有较高的准确率、较低的误报率和漏报率及较好的鲁棒性,适用于大数据下检测DDoS攻击. A DDoS attack detection method based on combination correlation and random forest( RF)was proposed. The network flow combination correlation degree( CCD) was defined based on the nonsymmetric and the semi-double interaction characterizes of attack flow;and the two tuples form of address correlation statistics( ACS) and unidirectional flow semi interaction( UFSI) was used as the feature of the network flow in CCD. Then the genetic algorithm with the CCD feature sequences was used for the optimization of two key parameters of the decision tree in the RF,namely,the number of maximum trees and the maximum depth of the decision tree. And the RF model within optimized parameters was applied to train the classification model which could be used for the DDoS attack detection. The experiment suggested that the proposed method was suitable for detecting the DDoS attack in big data environment with higher accuracy rate,lower false alarm rate,and missing alarm rate compared with existing DDoS attack detection methods.
作者 李梦洋 唐湘滟 程杰仁 刘译夫 LI Mengyang;TANG Xiangyan;CHENG Jieren;LIU Yifu(Key Laboratory of Internet Information Retrieval of Hainan Province,Hainan University,Haikou 570228,China;College of Information Science and Technology,Hainan University,Haikou 570228,China;State Key Laboratory of Marine Resource Utilization in South China Sea,Haikou 570228,China)
出处 《郑州大学学报(理学版)》 CAS 北大核心 2019年第2期23-28,39,共7页 Journal of Zhengzhou University:Natural Science Edition
基金 海南省自然科学基金项目(617048 2018CXTD333) 国家自然科学基金项目(61762033 61702539) 湖南省自然科学基金项目(2018JJ3611) 浙江省公益技术应用社会发展项目(LGF18F020019) 海南大学博士启动基金项目(kyqd1328) 海南大学青年基金项目(qnjj14444) 南海海洋资源利用国家重点实验室项目 海南省Internet信息检索重点实验室项目
关键词 DDOS攻击检测 网络流特征提取 遗传算法优化 随机森林 DDoS attack detection network flow feature extraction optimization by genetic algorithm random forest
  • 相关文献

参考文献2

二级参考文献2

共引文献23

同被引文献32

引证文献5

二级引证文献41

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部