首页 | 本学科首页   官方微博 | 高级检索  
     

全网异常流量簇的检测与确定机制
引用本文:杨雅辉, 杜克明. 全网异常流量簇的检测与确定机制[J]. 计算机研究与发展, 2009, 46(11): 1847-1853.
作者姓名:杨雅辉  杜克明
作者单位:1. 北京大学软件与微电子学院,北京,102600
2. 西安电子科技大学通信工程学院,西安,710071
摘    要:在网络安全管理领域,自动确定异常流量簇可为ISP分析和定位全网流量异常提供有效手段.提出了一种基于过滤的网络流数据的全网异常流量簇检测及确定机制.给出了问题的形式化描述和定义;扩展和改进了基于多维树的大流量簇检测方法,提出了灵活的“检测阈值”及“分裂值”的计算方法以改善大流量簇的检测精度;通过剪枝算法缩减了树的规模,提高了查找大流量簇的效率;给出了基于大流量簇确定异常流量簇的方法.实验表明该方法是可行的,可应用于全网异常诊断.

关 键 词:异常检测  异常流量簇  网络流  检测阈值

Identification of Anomalous Traffic Clusters for Network-Wide Anomaly Analysis
Yang Yahui, Du Keming. Identification of Anomalous Traffic Clusters for Network-Wide Anomaly Analysis[J]. Journal of Computer Research and Development, 2009, 46(11): 1847-1853.
Authors:Yang Yahui  Du Keming
Abstract:In the field of network security management, a number of recent researches have been dedicated to network-wide anomaly detection. But little attention has been paid to further identifying the anomalous traffic clusters which have been involved in the anomaly. Automatic identification of anomalous traffic clusters helps ISP providers to analyze and locate network anomalies for network and security management. The authors propose a method to detect and identify anomalous traffic clusters based on the filtered netflow data. The problems to be solved are described and defined formally; The Trie-based solution for detecting heavy hitters in a multi-dimensional tree is adapted and improved; the practical and flexible methods are proposed to calculate the threshold used for detecting specific heavy hitters and splitting value used for guiding the construction of trees to improve the accuracy of the algorithm; The operation for trimming off branches of the trees is integrated with reconstruction of traffic volume to decrease the size of trees to improve the efficiency for searching for heavy hitters; The methods to identify anomalous traffic clusters based on specific heavy hitters are presented. Experiments show that the methods proposed are feasible for network-wide anomaly diagnosis.
Keywords:anomaly detection  anomalous traffic clusters  netflow  detection threshold
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机研究与发展》浏览原始摘要信息
点击此处可从《计算机研究与发展》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号