节点文献

数据挖掘在DoS攻击检测和防护中的研究和应用

【作者】 衷宜

【导师】 刘凤玉;

【作者基本信息】 南京理工大学 , 模式识别与智能系统, 2003, 硕士

【摘要】 针对近年来网络入侵行为日益猖獗,多起分布式拒绝服务(DDoS)攻击事件发生的严峻现实,本文致力于利用数据挖掘技术对DoS攻击检测和防护。在对网络攻击检测中数据挖掘的应用和DoS攻击流特征深入研究的基础上,创新地提出一种将数据包分析和流量分析共同用于DoS攻击特征挖掘的思路,即除了运用传统对数据包和通信连接的关联规则挖掘和序列模式挖掘外,额外增加利用趋势分析算法对网络的流量预测和分析,并将流量预测值与实际值比较结果作为DoS特征检测规则的关键属性之一。 同时本文通过对关联规则、模式序列和趋势分析的多种算法的深入的分析和比较,结合网络攻击检测的需求,为检测DoS攻击选择合适有效的算法;并为加快关联规则挖掘速度,提出Apriori算法的改进算法——AADD算法。 最后本文详细阐述了一个基于数据挖掘技术的DoS检测和防护系统的设计和实现。

【Abstract】 Under the critical condition that network intrusion activities become more rampant in recent years, especially quite a few DDoS attacks have happened lately, this paper focuses on the research of detecting and defending DoS attacks using DM (data mining) technology. Based on the study of prevalent DM technology in the detection of network intrusions and the characters of DoS attacks, this paper presents a new idea to detect and defend DoS attacks by integrating with packet analysis and flow analysis. That is in addition to traditionally producing association rules and frequent episodes rules from packets and connections, Trend Analysis algorithm is used to forecast and analyze the network flow, the compared results between forecast values and real values become one of the key attributes of rules to detect DoS attacks.By the way this paper chooses the more effective DM algorithms by deep study in quite a few known algorithms employed in association rules, frequent episodes rules and trend analysis. To speed up producing association rule, this paper also introduces the AADD algorithm which is a upgrade algorithm from Apriori.In the end this paper expounds the design and implement of a DoS detection and defense system based on DM technology.

  • 【分类号】TP311.13
  • 【被引频次】2
  • 【下载频次】198
节点文献中: 

本文链接的文献网络图示:

本文的引文网络