首页 | 本学科首页   官方微博 | 高级检索  
     

基于最大频繁序列模式挖掘的App-DDoS攻击的异常检测
引用本文:李锦玲, 汪斌强. 基于最大频繁序列模式挖掘的App-DDoS攻击的异常检测[J]. 电子与信息学报, 2013, 35(7): 1739-1745. doi: 10.3724/SP.J.1146.2012.01372
作者姓名:李锦玲  汪斌强
作者单位:国家数字交换系统工程技术研究中心 郑州 450002
基金项目:国家科技支撑计划(2011BAH19B0和国家高技术研究发展计划(2011AA01A103)资助课题
摘    要:为了动态、准确、高效地描述用户的访问行为,实现对不同应用层分布式拒绝服务(Application-layer Distributed Denial of Service, App-DDoS)攻击行为的透明检测,该文提出基于最大频繁序列模式挖掘的ADA_MFSP(App-DDoS Detection Algorithm based on Maximal Frequent Sequential Pattern mining)检测模型。该模型在对正常Web访问序列数据库(Web Access Sequence Database, WASD)及待检测WASD进行最大频繁序列模式挖掘的基础上,引入序列比对平均异常度,联合浏览时间平均异常度、请求循环平均异常度等有效检测属性,最终实现攻击行为的异常检测。实验证明:ADA_MFSP模型不仅能有效检测各类App-DDoS攻击,且有良好的检测灵敏度。

关 键 词:应用层分布式拒绝服务攻击   检测模型   频繁序列模式挖掘   异常度
收稿时间:2012-10-26
修稿时间:2013-02-18

Detecting App-DDoS Attacks Based on Maximal Frequent Sequential Pattern Mining
Li Jin-Ling, Wang Bin-Qiang. Detecting App-DDoS Attacks Based on Maximal Frequent Sequential Pattern Mining[J]. Journal of Electronics & Information Technology, 2013, 35(7): 1739-1745. doi: 10.3724/SP.J.1146.2012.01372
Authors:Li Jin-ling    Wang Bin-qiang
Abstract:In order to describe the users access behavior dynamically, efficiently and accurately, a novel detection model for Application-layer Distributed Denial of Service (App-DDoS) attack based on maximal frequent sequential pattern mining is proposed, named App-DDoS Detection Algorithm based on Maximal Frequent Sequential Pattern mining (ADA_MFSP). After mining maximal frequent sequential patterns of trained and detected Web Access Sequence Database (WASD), the model introduces sequence alignment, view time and request circulation abnormality to describe the behaviour of App-DDoS attacks, finally achieves the purpose of attack detection. It is proved with experiments that the ADA_MFSP model can not only detect kinds of App-DDoS attacks, but also has good detection sensitivity.
Keywords:Application-layer Distributed Denial of Service (App-DDoS) attack  Detection model  Frequent sequential pattern mining  Abnormality
本文献已被 万方数据 等数据库收录!
点击此处可从《电子与信息学报》浏览原始摘要信息
点击此处可从《电子与信息学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号