| 注册
首页|期刊导航|东南大学学报(自然科学版)|基于综合评分的DDoS检测分析报告系统

基于综合评分的DDoS检测分析报告系统

李星 刘骥琛 张千里

东南大学学报(自然科学版)2017,Vol.47Issue(z1):20-24,5.
东南大学学报(自然科学版)2017,Vol.47Issue(z1):20-24,5.DOI:10.3969/j.issn.1001-0505.2017.S1.004

基于综合评分的DDoS检测分析报告系统

DDoS detection and analysis system based on comprehensive scoring

李星 1刘骥琛 2张千里1

作者信息

  • 1. 清华大学中国教育和科研计算机网网络中心,北京100084
  • 2. 清华大学电子工程系,北京100084
  • 折叠

摘要

Abstract

Aiming at the problem that the distributed denial of service(DDoS)attacks often use va-rious methods, a comprehensive scoring algorithm is designed.The algorithm can combine several detection algorithms and give a comprehensive score to alarm the attacks.Due to that current DDoS detection algorithms can not provide the specific features of the attacks, an Apriori-Geo-AS algo-rithm and Kolmogorov-Smirnov test based port usage pattern classification algorithm are designed. By improving the Apriori algorithm,the source-address,port and geographic location information of the attack source are extracted more effectively.Compared the port usage pattern with the ideal port usage pattern through the Kolmogorov-Smirnov test,the attacker摧s port usage pattern is further deter-mined.Experimental results show that the comprehensive scoring based detection algorithm can achieve a false alarm rate of less than 0.2%.An analysis on the attack case in Tsinghua University campus network demonstrates the effectiveness of the attack analysis.

关键词

分布式拒绝服务攻击/异常检测/Apriori-Geo-AS算法/Kolmogorov-Smirnov检验

Key words

distributed denial of service/anomaly detection/Apriori-Geo-AS algorithm/Kolmog-orov-Smirnov test

分类

信息技术与安全科学

引用本文复制引用

李星,刘骥琛,张千里..基于综合评分的DDoS检测分析报告系统[J].东南大学学报(自然科学版),2017,47(z1):20-24,5.

基金项目

国家重点研发计划资助项目(2017YFB0503703). (2017YFB0503703)

东南大学学报(自然科学版)

OA北大核心CSCDCSTPCD

1001-0505

访问量0
|
下载量0
段落导航相关论文