基于CUSUM算法的LDoS攻击检测方法
DOI:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP393

基金项目:

国家自然科学基金(6187255)


Detecting lowrate DoS attacks based on cumulative sum algorithm
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    低速率拒绝服务(LDoS,Low-rate Denial of Service)攻击具有流量发送速率低、隐蔽性强、具有突发性以及造成危害大的特点,融入正常流量中难以被传统的DoS攻击检测机制发现.针对该攻击方式突发性特点,分析路由器受到LDoS攻击时流量特征的统计异常,将路由器入口流量的均值与正常阈值相比较,提出了基于累积和(CUSUM,Cumulative Sum)算法的检测方法.该方法基于突变假设检验,对到达流量分析变点前后流量的累积和特征,通过将分析得到的累积和与设定的门限值比较来实现LDoS攻击的检测.实验通过调整算法参数来优化检测性能,通过基于NS-2搭建的仿真实验平台表明该方法具有较好的检测性能.

    Abstract:

    Lowrate Denial of Service (LDoS) attacks ,with the characteristics of low traffic transmission rate, strong concealment, burstiness and great harm, are difficult to be detected by traditional DoS detection mechanism.According to the sudden characteristics of the attack mode,the statistical abnormality of the traffic characteristics is analyzed when the router is attacked by the LDoS attack. Comparing the mean value of the router's ingress traffic with the normal threshold, a detection method based on the CUSUM (Cumulative Sum) algorithm is proposed, which is based on the mutation hypothesis test, and the accumulation and characteristics of the flow before and after the change of the arrival flow analysis.The LDoS attack is detected by comparing the accumulated sum of the analysis with the set threshold.The experiment optimizes the detection performance by adjusting the algorithm parameters.The simulation experiment platform based on NS2 shows that the method has better detection performance.

    参考文献
    相似文献
    引证文献
引用本文

引用本文格式: 苟峰,余谅. 基于CUSUM算法的LDoS攻击检测方法[J]. 四川大学学报: 自然科学版, 2020, 57: 476.

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2019-05-27
  • 最后修改日期:2019-07-25
  • 录用日期:2019-08-28
  • 在线发布日期: 2020-05-26
  • 出版日期:
通知
自2024年3月6日起,《四川大学学报(自然科学版)》官网已迁移至新网站:https://science.scu.edu.cn/,此网站数据不再更新。
关闭