首页 | 本学科首页   官方微博 | 高级检索  
     

基于概要数据结构的全网络持续流检测方法
引用本文:周爱平,朱琛刚.基于概要数据结构的全网络持续流检测方法[J].计算机应用,2019,39(8):2354-2358.
作者姓名:周爱平  朱琛刚
作者单位:1. 泰州学院 计算机科学与技术学院, 江苏 泰州 225300;2. 计算机网络和信息集成教育部重点实验室(东南大学), 南京 211189;3. 东南大学 计算机科学与技术学院, 南京 211189
基金项目:国家自然科学基金资助项目(61802274);计算机网络和信息集成教育部重点实验室(东南大学)开放课题资助项目(K93-9-2017-01);泰州市科研启动基金资助项目(QD2016027)。
摘    要:持续流是隐蔽的网络攻击过程中显现的一种重要特征,它不产生大量流量且在较长周期内有规律地发生,给传统的检测方法带来极大挑战。针对网络攻击的隐蔽性、单监测点的重负荷和信息有限的问题,提出全网络持续流检测方法。首先,设计一种概要数据结构,并将其部署在每个监测点;其次,当网络流到达监测点时,提取流的概要信息并更新概要数据结构的一位;然后,在测量周期结束时,主监测点将来自其他监测点的概要信息进行综合;最后,提出流持续性的近似估计,通过一些简单计算为每个流构建一个位向量,利用概率统计方法估计流持续性,使用修正后的持续性估计检测持续流。通过真实的网络流量进行实验,结果表明,与长持续时间流检测算法(TLF)相比,所提方法的准确性提高了50%,误报率和漏报率分别降低了22%和20%,说明全网络持续流检测方法能够有效监测高速网络流量。

关 键 词:网络测量  持续流检测  网络攻击  概要数据结构  概率统计方法  
收稿时间:2019-02-13
修稿时间:2019-03-19

Detection method for network-wide persistent flow based on sketch data structure
ZHOU Aiping,ZHU Chengang.Detection method for network-wide persistent flow based on sketch data structure[J].journal of Computer Applications,2019,39(8):2354-2358.
Authors:ZHOU Aiping  ZHU Chengang
Affiliation:1. School of Computer Science and Technology, Taizhou University, Taizhou Jiangsu 225300, China;2. Key Laboratory of Computer Network and Information Integration of Ministry of Education(Southeast University), Nanjing Jiangsu 211189, China;3. School of Computer Science and Engineering, Southeast University, Nanjing Jiangsu 211189, China
Abstract:Persistent flow is an important feature of hidden network attack. It does not generate a large amount of traffic and it occurs regularly in a long period, so that it brings a large challenge for traditional detection methods. Network attacks have invisibility, single monitors have heavy load and limited information. Aiming at the above problems, a method to detect network-wide persistent flows was proposed. Firstly, a sketch data structure was designed and was deployed on each monitor. Secondly, when the network flow arrived at a monitor, the summary information was extracted from network data stream and one bit in the sketch data structure was updated. Thirdly, at the end of measurement period, the summary information from other monitors was synthesized by the main monitor. Finally, the approximate estimation of flow persistence was presented. A bit vector was constructed for each flow by some simple computing, flow persistence was estimated by using probability statistical method, and the persistent flows were detected based on revised persistence estimation. The experiments were conducted on real network traffic, and their results show that compared with the algorithm of Tracing Long Duration flows (TLF), the proposed method increases the accuracy by 50% and reduces the false positive rate, false negative rate by 22%, 20% respectively. The results illustrate that the method of detecting network-wide persistent flows can effectively monitor network traffic in high-speed networks.
Keywords:network measurement                                                                                                                        persistent flow detection                                                                                                                        network attack                                                                                                                        sketch data structure                                                                                                                        probabilistic statistical method
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号