期刊文献+

基于多维观测特征的MF-HMM模型识别新型LDoS驱动的高分散低速率QoS侵犯 被引量:1

Identifying New High-distributed Low-rate Qo S Violation Driven by LDo S Based on Multi-observed Features MF-HMM
下载PDF
导出
摘要 针对新型LDo S驱动的高分散低速率Qo S侵犯,提出一种新颖的基于网络微观和宏观多维特征的识别方法。在网络微观方面,加权计算了反应TCP包头内部微观变化的Flag控制位,以及计算了反应LDo S固有周期特性的I-I-P 3元组的功率谱密度PSD特征;在网络宏观方面,引入反应网络发送流和确认流比值变化的R特征,共同构成多维观测序列,采用多维隐马尔科夫混合模型multi-stream fused HMM(MF-HMM)自动识别Qo S侵犯。同时,应用Kaufman算法动态调整阈值。大量实验表明,提出的方法有效降低了识别的误报率和漏报率,特别针对新型LDo S驱动的高分散低速率Qo S侵犯,在复杂网络背景流量下依然具有很高的识别率。 To detect new high-distributed low-rate Qo S violation driven by LDo S attack and guarantee high network Qo S,a novel recognition scheme was proposed with the consideration of multiple network features in both macro and micro aspects. At micro-level feature,the weighted sum of FLAG control bits was used to describe an internal micro-change in TCP package header. Meanwhile,the power spectral density( PSD) feature of I-I-P triple was calculated in order to reflect the inherent periodicity of LDo S Attack; at macro-level feature,R feature was introduced to mark the change in ratio of sent_flow and received_flow. Multi-dimensional observation state sequences can be constituted with these features that further form multi-stream fused hidden Markov model( MF-HMM). MF-HMM was applied to automatically recognize Qo S violation. In addition,Kaufman algorithm was used to dynamically adjust and upgrade threshold value. Experiments showed that the approach effectively reduces the false-positive rate and false-negative rate in recognition. Moreover,it has an especially high recognition rate for new high-distributed low-rate Qo S violation driven by LDo S even in complexity background network traffic.
出处 《四川大学学报(工程科学版)》 EI CAS CSCD 北大核心 2015年第1期42-48,共7页 Journal of Sichuan University (Engineering Science Edition)
基金 国家自然科学基金资助项目(60703023 61170265) 吉林省科技发展计划资助项目(20090110)
关键词 MULTI-STREAM FUSED HMM 网络Qo S 功率谱密度PSD Kaufman算法 multi-stream fused HMM network Qo S power spectrum density PSD Kaufman algorithm
  • 相关文献

参考文献4

二级参考文献23

共引文献39

同被引文献3

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部