首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于小波分析的DDoS攻击检测方法
引用本文:任义龙,刘渊.一种基于小波分析的DDoS攻击检测方法[J].计算机工程与应用,2012,48(31):82-88.
作者姓名:任义龙  刘渊
作者单位:1.江南大学 物联网工程学院,江苏 无锡 214062 2.江南大学 数字媒体学院,江苏 无锡 214062
基金项目:国家自然科学基金(No.60875036).
摘    要:通过对网络流量的分形特性和分布式拒绝服务(DDoS)的特点进行研究,提出了一种基于小波分析的DDoS攻击检测方法,并设计了该方法检测攻击的模型。对网络流量的分形特性进行判断,然后对具有自相似特性和多重分形特性的网络流量,分别采用基于小波分析的Hurst指数方差法和基于多窗口小波分析的Holder指数法检测DDoS攻击。通过对DARPA 2000年数据的实验表明,该方法能够有效地检测到攻击,对大流量背景攻击、低速率攻击、反射式攻击也都达到了较高的检测率,比传统方法有效。

关 键 词:分布式拒绝服务  自相似性  多重分形  Hurst参数  Holder指数  多窗口小波分析  

Detecting method for DDoS attack based on wavelet analysis
REN Yilong , LIU Yuan.Detecting method for DDoS attack based on wavelet analysis[J].Computer Engineering and Applications,2012,48(31):82-88.
Authors:REN Yilong  LIU Yuan
Affiliation:1.School of Internet of Things Engineering, Jiangnan University, Wuxi, Jiangsu 214062, China 2.School of Digital Media, Jiangnan University, Wuxi, Jiangsu 214062, China
Abstract:On the basis of analyzing the fractal property of network traffic and the features of Distributed Denial of Service(DDoS) attacks, a method of DDoS attack detection based on wavelet analysis is presented, and the attack detection model is designed. It judges the fractal features of network traffic, then adopts a method of variance of Hurst exponent based on wavelet analysis detect attack when it is self-similar or a method of Holder exponent based on multi-window wavelet analysis detect attack when it is multi-fractal. On the DARPA/Lincoln laboratory intrusion detection evaluation data set 2000, the experimental results show that this method is effective, and detection rate is high on the big background traffic DDoS attack, low-rate DDoS attack, and reflection DDoS attack, which is better than the traditional method.
Keywords:Distributed Denial of Service(DDoS) self-similar multi-fractal Hurst parameter Holder exponent multi-window wavelet analysis
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号