摘要
提出一种基于概要数据结构(sketch)的网络异常检测方法。采用金字塔时间模型对高速网络数据流进行分析,并基于奇异熵提取sketch。统计一定周期内该数据结构的特征值变化趋势,计算出均值和梯度值,以及相应的报警区间。当告警出现时,该方法能分析出现异常的IP地址。实验证明,该方法能有效地对网络进行异常检测。
The article proposes a sketch data structure based network anomaly detection method.It analyzes high speed network data with pyramid time model and extracts sketch by singular entropy,collects the variation trend of data structure eigenvalue during a certain period,calculates its average and gradient values as well as its correspondent alarm scope.When alarm appears,the method can draw out exceptional IP addresses.Experiments prove that the method is effective in network anomaly detection.
出处
《计算机应用与软件》
CSCD
2011年第4期186-188,共3页
Computer Applications and Software
基金
陕西省自然科学基金项目(2009JM8001-1)
关键词
概要数据结构
金字塔时间模型
奇异熵
异常检测
Sketch data structure Pyramid time model Singular entropy Anomaly detection