节点文献

基于BloomFilter的大规模异常TCP连接参数再现方法

Reconstructing the Parameter for Massive Abnormal TCP Connections with Bloom Filter

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 龚俭彭艳兵杨望刘卫江

【Author】 GONG Jian1,2, PENG Yan-Bing1,2+, YANG Wang1,2, LIU Wei-Jiang1,2 1(Department of Computer Science and Technology, Southeast University, Nanjing 210096, China) 2(Jiangsu Provincial Key Laboratory of Computer Network Technology, Nanjing 210096, China)

【机构】 东南大学计算机科学与工程系东南大学计算机科学与工程系 江苏南京210096江苏省计算机网络重点实验室江苏南京210096江苏南京210096江苏省计算机网络重点实验室

【摘要】 提出由TCP连接的唯一性导出的TCP数量平衡性测度及其经验范围可用于检测TCP连接的大规模异常,如DDoS、扫描等.使用带哈希增强算法的BloomFilterReproduction(BFR)方法对TCP连接大规模异常的参数进行快速再现,如IP地址、端口的分布等,使得在检测过程中无须维护TCP五元组的信息.实验结果表明,该方法能够以较少的资源占用和较高的准确性来揭示网络流量中混杂的多种异常现象.

【Abstract】 The large scaled TCP abnormal behavior, such as DDoS, scanning etc., can be detected by some metrics and their experimental values derived by the uniqueness of TCP connections. An algorithm named Bloom Filter Reproduction (BFR) is proposed to reconstruct the original parameters in large scaled TCP abnormal behaviors pithily by enhanced simple hash functions. Without maintaining the TCP information of 96bits’ 5-tuple, the BFR algorithm can reconstruct the abnormal parameters such as IP address or their aggregation timely during the detection process. The experiments show that BFR can disclose several abnormal behaviors mixed in network traffic at the same time with high precision and low overhead.

【基金】 国家重点基础研究发展规划(973);教育部科学技术重点研究项目;江苏省网络与信息安全重点实验室~~
  • 【文献出处】 软件学报 ,Journal of Software , 编辑部邮箱 ,2006年03期
  • 【分类号】TP393.08
  • 【被引频次】60
  • 【下载频次】520
节点文献中: 

本文链接的文献网络图示:

本文的引文网络