首页 | 本学科首页   官方微博 | 高级检索  
     

基于网络全局流量异常特征的DDoS攻击检测
引用本文:罗华,胡光岷,姚兴苗.基于网络全局流量异常特征的DDoS攻击检测[J].计算机应用,2007,27(2):314-317.
作者姓名:罗华  胡光岷  姚兴苗
作者单位:电子科技大学通信与信息工程学院 四川成都610054
基金项目:国家自然科学基金 , 四川省青年科技基金
摘    要:由于分布式拒绝服务(DDoS)攻击的隐蔽性和分布式特征,提出了一种基于全局网络的DDoS检测方法。与传统检测方法只对单条链路或者受害者网络进行检测的方式不同,该方法对营运商网络中的OD流进行检测。该方法首先求得网络的流量矩阵,利用多条链路中攻击流的相关特性,使用K L变换将流量矩阵分解为正常和异常流量空间,分析异常空间流量的相关特征,从而检测出攻击。仿真结果表明该方法对DDoS攻击的检测更准确、更快速,有利于DDoS攻击的早期检测与防御。

关 键 词:分布式拒绝服务攻击  全局流量异常  流量矩阵
文章编号:1001-9081(2007)02-0314-04
收稿时间:2006-08-31
修稿时间:2006-09-04

DDoS attack detection based on global network properties of network traffic anomaly
LUO Hua,HU Guang-min,YAO Xing-miao.DDoS attack detection based on global network properties of network traffic anomaly[J].journal of Computer Applications,2007,27(2):314-317.
Authors:LUO Hua  HU Guang-min  YAO Xing-miao
Affiliation:School of Communication and Information Engineering, University of Enectronic Science and Technology of China,Chengdu Sichuan 610054, China
Abstract:Due to the invisibility and distributivity characteristics of Distributed Denial of Service (DDoS) attack, a new DDoS detection method based on global network was presented in this paper. Our method detects DDoS by analyzing OD traffic matrix, whereas the traditional methods detect it on single link or victim network. This method was carried out as follows: First, we need to get network traffic matrix in order to obtain the correlation character of attack traffic among multiple links. Then, traffic matrix was divided into normal space and abnormal space by K-L transformation. Finally, the correlation of abnormal space was achieved to detect DDoS attack. The simulation result shows that this proposed method is more accurate and faster than traditional methods. It is in favor of earlier detection of DDoS attack.
Keywords:Distributed Denial of Service (DDoS) attack  global network traffic anomaly  Traffic Matrix(TM)  
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号