首页 | 本学科首页   官方微博 | 高级检索  
     

基于聚类分流算法的分布式蜜罐系统设计
引用本文:柏青,苏旸.基于聚类分流算法的分布式蜜罐系统设计[J].计算机应用,2013,33(4):1077-1080.
作者姓名:柏青  苏旸
作者单位:1. 武警工程大学 电子技术系, 西安 710086 2. 武警工程大学 网络与信息安全研究所,西安 710086
基金项目:国家自然科学基金资助项目,陕西省自然科学基础研究计划项目
摘    要:针对现有的网络安全防御系统主动性不足,对未知类型网络数据的判断速度慢、准确性不高的缺陷,设计了一种应用聚类算法对未知类型数据进行聚类分流的分布式蜜罐系统。在聚类过程中,采用一种改进的聚类中心选择算法,对未知类型网络数据进行模糊聚类,将聚类失败的数据分流到蜜罐中进行特征学习,从而尽早地发现新的攻击类型,减轻蜜罐的监控和记录压力,降低蜜罐被攻破的概率,有利于防御时采用更为有效的防御策略。此系统应用在政府某部门的专网中,实验结果验证了在不明显增加系统计算量的情况下,该聚类算法比平均值聚类算法有更高的聚类成功率。

关 键 词:蜜罐  聚类算法  初始类中心  数据分流  专网  
收稿时间:2012-10-26
修稿时间:2012-12-05

Design of distributed honeypot system based on clustering and data shunting algorithm
BAI Qing , SU Yang.Design of distributed honeypot system based on clustering and data shunting algorithm[J].journal of Computer Applications,2013,33(4):1077-1080.
Authors:BAI Qing  SU Yang
Affiliation:1. Department of Electronic Technology, Engineering University of Chinese Armed Police Force, Xi'an Shaanxi 710086, China
2. Institute of Network and Information Security, Engineering University of Chinese Armed Police Force, Xi'an Shaanxi 710086, China
Abstract:Concerning the lack of activity, the low speed and accuracy of recognizing attacks of the current network security defense system, this paper proposed a distributed honeypot system. During the process of clustering, an improved clustering center selection algorithm was used to cluster the data of the network in a fuzzy way, so as to divide the unclassified data into the honeypot to learn their features. Then a new type of attack can be detected as soon as possible. This design can not only lighten the supervising and recording pressure of honeypots, lower the broken rate of the honeypot, but also help us adopt more effective defense strategy. This system can be used in the private networks of some government. The clustering algorithm used in this paper has a higher rate of success than the average clustering algorithm without increasing the amount of computations of the system obviously.
Keywords:honeypot                                                                                                                          clustering algorithm                                                                                                                          initial clustering center                                                                                                                          data shunting                                                                                                                          private network
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号