节点文献
网络流量监测技术的研究及其在安全管理中的应用
【作者】 杜瑞峰;
【导师】 谭汉松;
【作者基本信息】 中南大学 , 计算机应用技术, 2005, 硕士
【摘要】 伴随着Internet的迅速发展,网络安全事件开始频繁发生,各种攻击手段层出不穷,计算机网络的保密性、完整性和可用性受到了严峻考验。分布式拒绝服务DDoS攻击就是目前一种危害极大的攻击方式,给网络服务器带来严重的威胁,也给千千万万的网络用户造成了损失。 网络流量监测技术已经成为保证现代网络管理性能的重要手段,在网络的配置管理、故障管理、性能管理、安全管理和计费管理等方面发挥着不可替代的作用。本文研究的目的是通过对网络流量监测技术进行研究,然后应用到DDoS攻击的监测和防御中。 简单网络管理协议SNMP是目前网络管理的基础,已经得到了得到广泛应用,本文对SNMP进行了详细的介绍和探讨,并分析了SNMP的发展趋势;流量数据的采集是整个流量监控系统的基础,文章对现有的数据采集技术进行了分类,然后深入地研究了基于NetFlow技术的网络流量采集技术;在研究分析了几种网络流量异常检测算法的基础上,提出了一种改进的广义似然估计(IGLR)的检测算法。 在分布式拒绝服务DDoS攻击发生时,由于会使用大量的虚假IP地址,因此受害者所在的网段上网络流量显著增加,并且在流量中新源IP地址产生的数据包的百分比明显上升。借助开放源代码实现了NetFlow技术,对流量数据进行采集,运用IGLR算法进行网络流量异常检测,运用方差分析算法对新源IP地址产生的数据包比重进行检测,设计实现了一种基于流量监测技术的DDoS攻击检测与防御,实验表明效果良好,但是如果将系统应用到实际的高性能网络环境中,还需要考虑到数据量、速度等等问题,解决这些问题是进一步研究的重点。
【Abstract】 With the boom of the Internet, the network security events occur frequently and there are more and more attach means. So privacy, integrality and availability of network are facing a hard challenge. DDoS (Distributed Denial of Service), which has brought much loss for millions of network users, is one of the most ruinous means and a bad threaten for the servers.As an important means of assuring the performance of modem network, network traffic monitoring has indispensability function for the configuration management, faults management, performance management, security management and cost-accounting management. This paper would like to study the technologies of network traffic monitoring and employ them to detect and defend against the DDoS attacks.Simple Network Management Protocol (SNMP), which has been employed extensively, is the foundation of network management. In this paper the SNMP discussed detailedly, and its evolution trend is analyzed. Collection of the flow data is the foundation of a traffic monitoring system. The existing techniques of flow data collection are classed, and the NetFlow-based method is discussed deeply. On the basis of studying the algorithms of network traffic abnormality detection, an improved Generalized Likelihood Ratio (IGLR) algorithm is proposed.When a DDoS attack happens, the network traffic will increase evidently, and the percent of packets with new IP addresses in the network traffic will increase evidently too because a lot of spoofed and mendacious IP addresses are used. So a DDoS detection and protection system is designed and implemented. In this system, NetFlow, implemented with open source code, is used as the mean of traffic data collection, and the IGLR algorithm is employed to detect the abnormality of network traffic, and the analysis of variance (ANOVA) algorithm is employed to detect the abnormality of the percent of the new packets with new addresses. Our experiments show that the DDoS detection andprotection system has nice performance. However in the high performance network, some problems must be considered, such as the magnitude of flow data, rate etc. So solving these problems is the importance of the next step.
- 【网络出版投稿人】 中南大学 【网络出版年期】2006年 05期
- 【分类号】TP393.06
- 【被引频次】10
- 【下载频次】399