期刊导航

论文摘要

基于CUSUM算法的LDoS攻击检测方法

Detecting low rate DoS attacks based on cumulative sum algorithm

作者:苟峰(四川大学计算机学院);余谅(四川大学计算机学院)

Author:GOU Feng(College of Computer Science,Sichuan University);YU Liang(College of Computer Science,Sichuan University)

收稿日期:2019-05-27          年卷(期)页码:2020,57(3):476-482

期刊名称:四川大学学报: 自然科学版

Journal Name:Journal of Sichuan University (Natural Science Edition)

关键字:低速率拒绝服务;CUSUM;攻击检测

Key words:Low-rate denial of service; CUSUM; Attacks detection

基金项目:国家自然科学基金(6187255)

中文摘要

低速率拒绝服务(LDoS,Low-rate Denial of Service)攻击具有流量发送速率低、隐蔽性强、具有突发性以及造成危害大的特点,融入正常流量中难以被传统的DoS攻击检测机制发现.针对该攻击方式突发性特点,分析路由器受到LDoS攻击时流量特征的统计异常,将路由器入口流量的均值与正常阈值相比较,提出了基于累积和(CUSUM,Cumulative Sum)算法的检测方法.该方法基于突变假设检验,对到达流量分析变点前后流量的累积和特征,通过将分析得到的累积和与设定的门限值比较来实现LDoS攻击的检测.实验通过调整算法参数来优化检测性能,通过基于NS-2搭建的仿真实验平台表明该方法具有较好的检测性能.

英文摘要

Low rate Denial of Service (LDoS) attacks ,with the characteristics of low traffic transmission rate, strong concealment, burstiness and great harm, are difficult to be detected by traditional DoS detection mechanism.According to the sudden characteristics of the attack mode,the statistical abnormality of the traffic characteristics is analyzed when the router is attacked by the LDoS attack. Comparing the mean value of the router's ingress traffic with the normal threshold, a detection method based on the CUSUM (Cumulative Sum) algorithm is proposed, which is based on the mutation hypothesis test, and the accumulation and characteristics of the flow before and after the change of the arrival flow analysis.The LDoS attack is detected by comparing the accumulated sum of the analysis with the set threshold.The experiment optimizes the detection performance by adjusting the algorithm parameters.The simulation experiment platform based on NS 2 shows that the method has better detection performance.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065