节点文献

入侵检测系统评估数据的自相似性研究

Research on the Self-similarity of Evaluation Data for Intrusion Detection Systems

【作者】 黄昆

【导师】 张大方;

【作者基本信息】 湖南大学 , 计算机应用技术, 2004, 硕士

【摘要】 入侵检测系统是计算机网络安全防御系统的重要组成部件之一。随着入侵检测系统的广泛应用,入侵检测系统的定量化评估成为研究热点。1998年和1999年美国麻省理工学院林肯实验室(MIT/LL)提出了一个目前应用最广泛的定量化评估入侵检测系统的测试方法和测试平台,更重要的是公开发布了作为测试基准的入侵检测系统评估数据集。但是MIT/LL评估数据的网络流量统计特性等重要信息没有提供,而且MIT/LL评估数据存在攻击实例分布不合理等缺陷。 首先,本文对1999年MIT/LL评估数据第1周和第3周背景流量的协议分布统计特性和数据速率进行分析研究。比较评估数据第1周和第3周背景流量的实际时间与MIT/LL提供的时间是否一致;分析评估数据第1周和第3周背景流量中网络层,传输层和应用层协议的分布特性,指出影响整个背景流量的网络行为特性的主要协议;分析评估数据第1周和第3周背景流量中帧数据包的数据速率和网络带宽利用率。 其次,本文使用方差时间图估计法,R/S分析估计法,周期图估计法,Whittle估计法和基于小波分析的Abry-Veitch估计法对1999年MIT/LL评估数据第1周和第3周背景流量中帧数据包到达过程和IP数据包到达过程的Hurst参数值进行估计。分析评估数据第1周和第3周背景流量每天表现出的自相似性,指出背景流量每天在前十多个小时内表现出自相似性,在其他一些时间内不表现出自相似,而且在内部网络和外部网络表现出的自相似性是不一致的。对背景流量不表现出自相似性的可能原因进行探索和研究。 最后,本文讨论几种探测扫描攻击和拒绝服务攻击的产生原理和实现。这些攻击的攻击流量是用于评估入侵检测系统的检测躲避攻击的能力。

【Abstract】 Intrusionn detection system is one of important components of computer network security defense system. With the widespread use of intrusion detection systems, research on evaluation of intrusion detection systems has been a hot focus. In 1998 and 1999, Lincoln Laboratory of Massachusetts Institute of Technology (MIT/LL) presented the most comprehensive approach and test bed for quantitative evaluation of intrusion detection systems, and it is more important that evaluation data set for intrusion detection systems benchmaking has been publically distributed. But the network traffic statistical characteristic of MIT/LL evaluation data has not been provided and there are some flaws in MIT/LL evaluation data, including unreasonable distribution of attack instances and so on.First, this paper presents the analysis of statistical charaterisitc of protocol distribution and data speed of background traffic of 1999 MIT evaluation data in week 1 and 3. The actual time of background traffic in week 1 and 3 is compared with what is provided by MIT/LL; the distribution of network layer protocol, transport layer protocol and application layer protocol of background traffic in week 1 and 3 is analyzed and the main protocols that affect network activity characteristic of background traffic are indicated; data speed and network bandwidth utilization rate of background traffic in week 1 and 3 are also analyzed.Second, Hurst parameter of frame arrivals process and ip arrivals process of background traffic of 1999 MIT evaluation data in week 1 and 3 is estimated with variance-time plots estimator, R/S analysis estimator, periodgram estimator, Whittle estimator and Wavelet-based Abry-Veitch estimator. Self-similarity that background traffic exhibits every day in week 1 and 3 is analyzed and it is indicated that self-similarity is exhibited in the period of fore more than 10 hours and not in the period of other some hours every day and self-similarity background traffic exhibits is different between in inside networks and in outside networks. The likely causes are explored that background traffic fails to exhibit self-similarity.Final, the principle and implementation of several probe scanning attacks and denial-of-services attacks are dicussed. Attack traffic of these attacks is aim to evaluating the capability of detecting evasion attacks.

  • 【网络出版投稿人】 湖南大学
  • 【网络出版年期】2004年 04期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】196
节点文献中: 

本文链接的文献网络图示:

本文的引文网络