欢迎访问《空军工程大学学报》官方网站!

咨询热线:029-84786242 RSS EMAIL-ALERT
基于多维信息熵值的DDoS攻击检测方法
DOI:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP393

基金项目:

陕西省自然科学基金资助项目(2012JZ8005)


Detection DDoS Attack Based on Multi-Dimensional Entropy
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对互联网中日益严重的分布式拒绝服务攻击行为,提出了一种基于多维信息熵值的DDoS攻击检测方法。首先根据DDoS攻击的特点,采用条件熵及相异熵构建具有良好区分度的多维攻击检测向量,在此基础上采用滑动窗口的多维无参数CUSUM算法放大正常流量与攻击流量的差异来实现DDoS攻击的检测。通过实际网络攻击流量及合成攻击流量测试表明:文中提出的算法能够检测到LLS-DDoS数据集及合成数据集中的全部攻击,算法对于DDoS攻击的响应速度快,能够应用于高速骨干网络中。

    Abstract:

    In order to detect the increasingly serious distributed denial of service (DDoS) attack on the internet, an algorithm for detecting DDoS attack based on multi-dimensional information entropy is proposed. First of all, according to the property of DDoS attack, the multi-dimensional detecting vector which is capable of distinguishing attack from normal traffic is constructed based on conditional entropy and discrepant entropy. Then the sliding multi-dimensional non-parameter CUSUM algorithm with the capability of amplifying the discrepancy between normal and abnormal network traffic is adopted to detect DDoS attack. The experiments over actual and composite network attack traffic show that the proposed algorithm can detect all the DDoS attacks in both traces. Meantime, the proposed algorithm is capable of detecting DDoS attack quickly and it can be applied in the high backbone network.

    参考文献
    相似文献
    引证文献
引用本文

赵小欢,夏靖波,郭威武,杜华桦.基于多维信息熵值的DDoS攻击检测方法[J].空军工程大学学报,2013,(3):58-62

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2015-11-24
  • 出版日期: