首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于流时间影响域的网络流量异常检测
引用本文:徐久强,周洋洋,王进法,赵海.基于流时间影响域的网络流量异常检测[J].东北大学学报(自然科学版),2019,40(1):26-31.
作者姓名:徐久强  周洋洋  王进法  赵海
作者单位:东北大学 计算机科学与工程学院,辽宁 沈阳,110169;东北大学 计算机科学与工程学院,辽宁 沈阳,110169;东北大学 计算机科学与工程学院,辽宁 沈阳,110169;东北大学 计算机科学与工程学院,辽宁 沈阳,110169
基金项目:中央高校基本科研业务费重大科技创新项目(N161608001).
摘    要:针对如何提高网络流量异常行为检测准确率的问题,提出基于网络流时间影响域(TID)的网络流量检测模型.通过分析正常和异常情况下流量网络模型平均度的变化,构建了基于复杂网络平均度指标的网络流量异常检测算法.实验结果表明,基于网络流时间影响域的流量网络模型能合理地描述网络流量间的依赖关系,具有良好的检测性能,同时该网络模型仅需时间戳、源IP、目的IP三维网络特征即可实现,检测方法适用于绝大多数网络类型,检测效率优于其他网络流量异常检测方法,具有较高的普适性.

关 键 词:网络流量  异常检测  流时间影响域  流量网络模型  网络平均度
收稿时间:2017-10-18
修稿时间:2017-10-18

Anomaly Detection of Network Traffic Based on Flow Time Influence Domain
XU Jiu-qiang,ZHOU Yang-yang,WANG Jin-fa,ZHAO Hai.Anomaly Detection of Network Traffic Based on Flow Time Influence Domain[J].Journal of Northeastern University(Natural Science),2019,40(1):26-31.
Authors:XU Jiu-qiang  ZHOU Yang-yang  WANG Jin-fa  ZHAO Hai
Institution:School of Computer Science & Engineering, Northeastern University, Shenyang 110169, China.
Abstract:Aiming at improving the accuracy rate of anomaly network traffic detection, a network traffic detection model was proposed based on the time influence domain(TID)of network flow. By analyzing the changes of average degree of traffic network model under the normal and abnormal conditions, an anomaly detection algorithm of network traffic based on the average degree metric of complex network was developed to detect the abnormal traffic. Experimental results show that based on the flow time influence domain, the anomaly detection model of traffic network can reasonably describe the inter-dependency relationship between network traffic. The proposed method has a better detection performance, meanwhile only three network features, i.e. timestamp, source IP and destination IP, are needed to implement the above model. Detection efficiency is better than other methods. The method proposed meets most network types and has a better ubiquity.
Keywords:network traffic  anomaly detection  flow time influence domain  traffic network model  network average degree  
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《东北大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《东北大学学报(自然科学版)》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号