首页> 外文学位 >A new approach to network traffic anomaly detection.
【24h】

A new approach to network traffic anomaly detection.

机译:一种用于网络流量异常检测的新方法。

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection system (IDS) is a device or software that monitors the events or activities in the network or computer systems and analyzes them for possible security policy violations. When any sign of suspicious activity has been found, the system will alarm the system or report the incident to the network administrator for further analysis.;Anomaly detection is one of the main methods of designing intrusion detection systems (IDS). It is assumed that the malicious behavior is anomalous; therefore, violations of security policies could be detected from abnormal patterns of usage. Anomaly-based detection establishes a performance baseline based on normal network traffic evaluations. This baseline will be used to identify the state of current network traffic activity. It is considered normal when network traffic evaluation falls within baseline parameters. If the current network traffic is outside baseline parameters, the "abnormal activity" alert occurs and the alarm is triggered in the system.;Several methods have been studied for designing anomaly detection. In this research, we present a new approach for network traffic anomaly detection based on a denoising algorithm. The approach is to examine the statistics of the network traffic in the normal condition and consider it as noise. When the suspected attacks take place, the traffic pattern changes according to amount or volume, and those changes in pattern will be considered "regions of interest" determined by the energy distribution analysis. We investigate documented denoising algorithms applied to network traffic data so as to detect anomalies in regions of interest in the traffic data. A new anomaly detection algorithm based on denoising algorithms was developed. To improve the performance of the algorithm, a combination of statistical method, and cumulative sum (CUSUM) and denoising methods were used.
机译:入侵检测系统(IDS)是一种设备或软件,可以监视网络或计算机系统中的事件或活动,并分析它们是否违反安全策略。当发现任何可疑活动的迹象时,系统将向系统发出警报或将事件报告给网络管理员以进行进一步分析。异常检测是设计入侵检测系统(IDS)的主要方法之一。假定恶意行为是异常的;因此,可以从异常使用模式中检测到违反安全策略的情况。基于异常的检测会基于正常的网络流量评估来建立性能基准。该基准将用于识别当前网络流量活动的状态。当网络流量评估落入基线参数之内时,这被认为是正常的。如果当前网络流量超出基线参数,则会发生“异常活动”警报,并在系统中触发警报。;已经研究了几种设计异常检测的方法。在这项研究中,我们提出了一种基于降噪算法的网络流量异常检测新方法。该方法是检查正常情况下网络流量的统计并将其视为噪声。当发生可疑的攻击时,流量模式会根据数量或数量发生变化,这些模式的变化将被视为通过能量分布分析确定的“关注区域”。我们研究了应用于网络流量数据的有记录的降噪算法,以检测流量数据中感兴趣区域的异常。提出了一种基于去噪算法的异常检测算法。为了提高算法的性能,使用了统计方法以及累积和(CUSUM)和去噪方法的组合。

著录项

  • 作者

    Petsuwan, Wanchalearm.;

  • 作者单位

    Florida Institute of Technology.;

  • 授予单位 Florida Institute of Technology.;
  • 学科 Engineering Electronics and Electrical.;Computer Science.
  • 学位 Ph.D.
  • 年度 2010
  • 页码 229 p.
  • 总页数 229
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 农学(农艺学);
  • 关键词

  • 入库时间 2022-08-17 11:36:47

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号