首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于时频分析的分布式拒绝服务攻击的自动检测
引用本文:孙钦东,张德运,郑卫斌,胡国栋.基于时频分析的分布式拒绝服务攻击的自动检测[J].西安交通大学学报,2004,38(12):1247-1250,1255.
作者姓名:孙钦东  张德运  郑卫斌  胡国栋
作者单位:西安交通大学电子与信息工程学院网络研究所,710049,西安
基金项目:国家信息化计算机网络与信息安全基金资助项目 (2 0 0 1-研 1- 0 10 )
摘    要:研究了分布式拒绝服务 (DDoS)攻击的特点 ,定义了流连接密度 (FCD)的概念 ,并证明了FCD时间序列的非平稳特性 .据此 ,提出了一种新的基于时频分析的自动检测DDoS攻击的方法 ,该方法采用平滑魏格纳 维利分布对FCD时间序列进行时频变换 ,将FCD时间序列转换为二维空间内的波动能量分布 ,并有效抑制了二次交叉项的影响 ,然后使用经过样本训练的K最近邻分类器进行攻击识别 .实验结果表明 ,该检测方法能够比较准确地识别DDoS攻击 ,识别误差主要出现在网络状态切换阶段 ,这对攻击识别的影响很小 ,识别误差率仅为 4 2 6 % .

关 键 词:分布式拒绝服务  时频分析  魏格纳维利分布  K最近邻
文章编号:0253-987X(2004)12-1247-04

Automatic Detection of Distributed Denial of Service Attacks Based on Time-Frequency Analysis
Sun Qindong,Zhang Deyun,Zheng Weibin,Hu Guodong.Automatic Detection of Distributed Denial of Service Attacks Based on Time-Frequency Analysis[J].Journal of Xi'an Jiaotong University,2004,38(12):1247-1250,1255.
Authors:Sun Qindong  Zhang Deyun  Zheng Weibin  Hu Guodong
Abstract:Based on the analysis of distributed denial of service (DDoS) attacks, the flow connection density (FCD) is defined and the characteristic of non-stationary of FCD time series is proved. A new method to detect DDoS attacks is proposed based on the time-frequency analysis of FCD. The proposed method detects DDoS attacks by transforming the time series of FCD with smooth Winger-Ville distribution, to obtain the energy distribution of the time series in two-dimensional space and suppress the effect of the quadratic cross term, and then identifying DDoS by using the K-nearest neighbor classifier trained by samples. The experimental results show that the developed approach can detect DDoS attacks correctly, and identification errors mainly present to the switching stage of the network with little influence on the identification of DDoS attacks. Compared with the theoretic value, the identification error ratio is only 4.26%.
Keywords:distributed denial of service  time-frequency analysis  Wigner-Ville distribution  K-nearest neighbor  
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号