节点文献
基于自相似特性的网络业务流的研究
Research on the Self-similarity of Network Traffic
【作者】 毛蓝;
【导师】 刘渊;
【作者基本信息】 江南大学 , 计算机应用技术, 2007, 硕士
【摘要】 自从Leland等人在90年代初第一次明确的提出了网络流量中存在着自相似现象以来,研究人员发现不论网络的拓扑和业务如何,网络流量中都能检测到自相似特性。其中Hurst参数是评估自相似性的重要参数,本文提出一个新方法来评估网络自相似过程中的Hurst参数,并且使用人工合成数据和实际数据来测试,与基于小波的Hurst参数估计法做比较,实验表明该方法比小波法更快并且产生了很小的Hurst参数估计的置信区间。接着针对传统检测方法存在的问题,将这一新的Hurst参数评估方法应用到DoS攻击检测中,由H参数变化来检测DoS攻击。通过分析DARPA 1998入侵检测数据表明,基于该法的Hurst参数评估能够检测到DoS攻击,此法比传统的基于特征匹配的网络流量异常检测法在检测精度上有较大提高。由于网络的自相似性,传统的基于泊松过程和马尔科夫模型等已不能反映准备反映网络流量。因此本文研究了基于自相似性的网络流量预测,用QPSO(Quantum-behaved Particle Swarm Optimization)对预测自相似性网络流量的最小均值峰度LMK(Least Mean Kurtosis)方法进行优化,能够获得较小的SNR-1 (Signal to Noise Ratio)。通过对真实网络流量的仿真实验,表明该法比LMK(最小均值峰度)算法更能够对网络流量进行精确的预测。
【Abstract】 Since the seminal study of Leland, Taqqu, Willinger, and Wilson who pointed out the existence of scaling behavior in the network traffic, the so-called self-similarity, there is now ample evidence that scale-invariant burstiness is an ubiquitous phenomenon in a wide range of generalized data types, from local-area and wide-area networks to IP and ATM protocol stacks to copper and fiber optic transmission media.Hurst parameter is a very important parameter to evaluate network self-similarity. In this paper, a new method to estimate the Hurst parameter of the increment process in network traffic–a process that is assumed to be self-similar is presented. The confidence intervals are obtained for the estimates using the new method. This new method is then applied to pseudo-random data and to real traffic data. We compare the performance of the new method to that of the widely-used wavelet method, and demonstrate that the former is much faster and produces much smaller confidence intervals of the Hurst parameter estimate. And then the estimation based on Hurst parameter is used to detect DoS attack, researched on the affect of Hurst parameter change brought by DoS attack. By analyzing the 1998 DARPA Intrusion Detection Evaluation dataset, it is verify that this method can detect DoS attack, and is more reliable on the recognition of all kinds of DoS attack than any other method based on measure precision.The existence of self-similarity shows that Poisson or Markov process cannot accurately describe the real network traffic. In this paper, the traffic prediction on self-similarity is researched. Least Mean Kurtosis (LMK) based on QPSO, which can obtain signal error ratio less than LMK, is proposed to predict the self similar traffic. The simulation results with the real traffic traces show the accuracy efficiency of the model.