首页> 外文期刊>中兴通讯技术:英文版 >A Method for Detecting Wide-scale Network Traffic Anomalies
【24h】

A Method for Detecting Wide-scale Network Traffic Anomalies

机译:一种检测宽尺度网络流量异常的方法

获取原文
获取原文并翻译 | 示例
       

摘要

Network traffic anomalies refer to the traffic changed abnormally and obviously.Local events such as temporary network congestion,Distributed Denial of Service(DDoS)attack and large-scale scan,or global events such as abnormal network routing,can cause network anomalies.Network anomaly detection and analysis are very important to Computer Security Incident Response Teams(CSIRT).But wide-scale traffic anomaly detection requires extracting anomalous modes from large amounts of high-dimensional noise-rich data,and interpreting the modes;so,it is very difficult.This paper proposes a general method based on Principle Component Analysis(PCA)to analyze network anomalies.This method divides the traffic matrix into normal and anomalous subspaces,maps traffic vectors into the normal subspace,gets the distance from detected vector to average normal vector,and detects anomalies based on that distance.
机译:网络流量异常是指流量异常和显然。诸如临时网络拥塞,分布式拒绝服务(DDOS)攻击和大规模扫描等流域事件,或者是网络路由异常的全局事件,可能导致网络Anomalies.network异常检测和分析对计算机安全事件响应团队(CSIRT)非常重要。但是广泛的交通异常检测需要从大量的高维噪声数据中提取异常模式,并解释模式;所以,非常困难这篇论文提出了一种基于原理分量分析(PCA)的一般方法来分析网络异常。该方法将流量矩阵划分为正常和异常子空间,将流量向量映射到正常子空间中,从检测到的向量到平均法向量映射到平均法向量,并根据该距离检测异常。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号