首页> 外文期刊>電子情報通信学会技術研究報告. インターネットアーキテクチャ. Internet Architecture >Identifying Anomalous Traffic using Dynamic Programming based Differential Analysis Method
【24h】

Identifying Anomalous Traffic using Dynamic Programming based Differential Analysis Method

机译:基于动态规划的差分分析方法识别异常流量

获取原文
获取原文并翻译 | 示例
           

摘要

This paper proposes an identification method of anomalous traffic such as DDoS attacks to protect network or server resources. Identification results are used as ACL rules at routers and represented as a set of aggregated flows; such as source/destination IP address ranges (prefixes), source/destination port numbers and protocols. Requirements for the identification can be summarized as the following three conditions; 1) covering the anomalous traffic, 2) avoiding to cover normal traffic, 3) with small number of aggregated flows. To accomplish these requirements, we identify the anomalous traffic by comparing traffic before the anomaly and that after the anomaly and analyzing the difference between them. Then, we assume the difference as anomalous traffic, traffic before anomaly as normal traffic, and generate a set of aggregate flow that meets the above three requirements and achieves the highest score representing the requirements. Here, searching the set of above flow is combinatorial optimization, and cause computing explosion. In this paper, we adopt dynamic programming to reduce the computing time. We evaluate our algorithm by using actual DDoS traffic data and show that computation time does not exponentially increase as the conventional method does.
机译:为了保护网络或服务器资源,提出了一种DDoS攻击等异常流量的识别方法。识别结果在路由器上用作ACL规则,并表示为一组聚合流。例如源/目标IP地址范围(前缀),源/目标端口号和协议。识别要求可以概括为以下三个条件: 1)覆盖异常流量,2)避免覆盖正常流量,3)聚合流量少。为了满足这些要求,我们通过比较异常之前和异常之后的流量并分析它们之间的差异来识别异常流量。然后,我们将差异假设为异常流量,将异常之前的流量视为正常流量,并生成一组满足以上三个要求并达到代表该要求的最高分的聚合流。在这里,搜索以上流程的集合是组合优化,并导致计算爆炸。在本文中,我们采用动态编程来减少计算时间。我们通过使用实际的DDoS流​​量数据评估我们的算法,并表明计算时间不会像传统方法那样呈指数增长。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号