节点文献

基于相对熵的网络流量异常检测方法

Network traffic anomaly detection based on relative entropy

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张登银廖建飞

【Author】 ZHANG Deng-yin,LIAO Jian-fei College of Computer Science & Technology,Nanjing University of Posts and Telecommunications,Nanjing 210023,China

【机构】 南京邮电大学计算机学院

【摘要】 网络流量的异常检测是网络安全领域一个重要分支,目标是及时准确地检测网络中发生的突发攻击事件。现有流量异常检测方法如数据挖掘、小波分析等方法或因检测效果较差,或因算法复杂,难以满足实时在线流量检测的应用需求。文中引入信息熵概念,通过对网络流量进行分维和分层实时计算网络流量相对熵,提出了一种基于相对熵的流量异常检测方法,算法时间复杂度为O(N×log2N×D)。实验分析表明,当检测率达到0.80~0.85时,误报率控制在0.03~0.05,可同时满足系统实时性和准确性要求。

【Abstract】 The anomaly detection of network traffic,which aims at detecting abrupt attacks timely and accurately,is important in the field of network security.Existing detection methods,such as the methods based on data mining and wavelet analysis,fail to meet the application requirements of online traffic detection either due to the high complexity of algorithm or the poor detection effect.By introducing the concept of information entropy and calculating relative entropy of the network traffic on the vision of the traffic’s dimensions and hierarchies in real-time,this paper proposes a relative entropy based detection method with the time complexity of algorithm at O(N×log2N×D).Experiment analysis shows that the false alarm rate can be controlled only in 0.03~0.05 when the detection rate reaches 0.8~0.85,which meets the requirements of real-time and accuracy simultaneously.

【关键词】 网络流量异常检测信息熵
【Key words】 network trafficanomaly detectioninformation entropy
【基金】 国家自然科学基金(61071093);国家高技术研究发展计划(863计划)(2010AA701202);瑞典—亚洲国际合作项目(348-2008-6212);留学回国人员项目(NJ209002);江苏省重大科技支撑计划(BE2009063);江苏高校优势学科(PAPD)资助项目
  • 【文献出处】 南京邮电大学学报(自然科学版) ,Journal of Nanjing University of Posts and Telecommunications(Natural Science) , 编辑部邮箱 ,2012年05期
  • 【分类号】TP393.08
  • 【被引频次】15
  • 【下载频次】340
节点文献中: 

本文链接的文献网络图示:

本文的引文网络