节点文献

多时间尺度同步的高速网络流量异常检测

Detecting Network Anomaly on Multi-Time-Scale

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王风宇云晓春曹震中

【Author】 Wang Feng-Yu~(1,2) Yun Xiao-Chun~1 Cao Zhen-Zhong~3 (1.Institute of Computing Technology,Chinese Academy of Sciences,Beijing 100080)2.Graduate University of Chinese Academy of Science, Beijing 100039)(3.Computer Science College,Qufu Normal University,Qufu 273165)

【机构】 中国科学院计算技术研究所信息智能与信息安全研究中心曲阜师范大学计算机科学学院

【摘要】 高速网络流量吞吐量大且复杂多变,对网络流量异常检测的准确性和及时性提出了挑战。本文提出了一种多时间尺度同步的异常检测算法 DA-MTS。该算法通过无抽取 Haar 小波变换对网络流量时间序列进行分解,获得不同时间尺度下的细节信号,去冗余后的无抽取 Haar 小波变换细节信号为平稳随机序列且逼近高斯白噪声,根据正态分布的“3σ”法则可以判断细节信号中的异常情况。随着新数据的获取,该算法能够同时在多个时间尺度上以递推方式进行无延后的异常检测,不但提高了异常检测的准确性,而且保证了异常发现的及时性。分析和实验表明,该方法能够显著提高网络异常检测的性能。

【Abstract】 Due to the volume and complexity of high-speed network traffic, it’s difficult to detect anomaly timely and precisely.In this paper, we proposed an anomaly detection algorithm that can progress on several time-scales synchronously. Firstly, pre-process the time series of traffic with non-decimated Haar wavelet transform to produce detail signals, which are stationary random series and follow Gaussian white noise, then detect anomaly on principal of"3 o "of normal distribution. Along with the arriving of new data, this algorithm detects anomaly on several time-scales recursively without delay, so it can detect anomaly precisely and timely.Analysis and experiments reveal that this algorithm can improve the performance of anomaly detection obviously, o

【基金】 国家自然科学基金 No.60573134;新世纪优秀人才支持计划.
  • 【会议录名称】 全国网络与信息安全技术研讨会论文集(上册)
  • 【会议名称】全国网络与信息安全技术研讨会
  • 【会议时间】2007-07
  • 【会议地点】中国山东青岛
  • 【分类号】TP393.08
  • 【主办单位】信息产业部互联网应急处理协调办公室
节点文献中: 

本文链接的文献网络图示:

本文的引文网络