节点文献

应用层异常检测方法研究

Research on Application Level Anomaly Detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 谢柏林余顺争王宇

【Author】 XIE Bai-lin YU Shun-zheng WANG Yu(Department of Electronics and Communication Engineering,Sun Yat-Sen University,Guangzhou 510275,China)

【机构】 中山大学电子与通信工程系

【摘要】 目前绝大部分异常检测方法只利用数据包的头部信息来检测网络攻击,即仅仅从网络层、传输层来分析网络的异常情况。而研究表明现在的网络攻击主要发生在应用层,因此从应用层来分析网络异常的研究就显得十分重要。首先介绍了入侵检测和异常检测的研究现状,突出强调了应用层异常检测的重要性,接着详细介绍了目前几种主要的应用层异常检测方法,最后讨论了应用层异常检测所面临的挑战。

【Abstract】 Most of the network anomaly detection approaches are based on packet header fields,while the payload is usually discarded,namely they detect network attacks only from network layer and transport layer.Unfortunately,most of today’s attacks happen on the application level,so the research of the application level anomaly detection is very important.We first introduced the current status of intrusion detection and network anomaly detection,and emphasized the importance of the application level anomaly detection.Then we introduced the main approaches of the application level anomaly detection in detail.Finally we discussed the challenges of the application level anomaly detection.

【关键词】 应用层异常检测网络安全
【Key words】 Application levelAnomaly detectionNetwork security
【基金】 国家高技术研究发展计划(“863”计划)(2007AA01Z449);国家自然科学基金-广东联合基金重点项目(U0735002)资助
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2009年04期
  • 【分类号】TP393.08
  • 【被引频次】7
  • 【下载频次】190
节点文献中: 

本文链接的文献网络图示:

本文的引文网络