作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 139-141. doi: 10.3969/j.issn.1000-3428.2007.16.048

• 安全技术 • 上一篇    下一篇

基于流连接信息熵的DDoS攻击检测算法

赵继俊,胡志刚,张 健

  

  1. (中南大学信息科学与工程学院,长沙 410083)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

DDoS Attacks Detection Algorithm Based on Flow Connection Entropy

ZHAO Ji-jun, HU Zhi-gang, ZHANG Jian

  

  1. (School of Information Science & Engineering, Central South University, Changsha 410083)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要: 分析了分布式拒绝服务(DDoS)攻击的特点,提出了流连接信息熵的定义,并通过对流连接信息熵时间序列的分析,采用非参数CUSUM算法进行DDoS攻击检测。该检测方法对固定IP、端口号随机变化的DDOS攻击有比较好的检测效果。实验结果证明,该方法能够以较高的精确度及时地检测出DDoS 攻击行为。

关键词: 分布式拒绝服务攻击, 相关数据包, 流连接信息熵, 非参数CUSUM算法

Abstract: On the basis of analyzing the features of distributed denial of service (DDoS) attacks, flow connection entropy time series analysis is proposed. It uses non-parametric CUSUM algorithm to complete the detection task of DDoS attacks. It minimizes the average delay of detection for a given false alarm rate. It has better detection effect on the fixed source IP and random destination ports’s DDoS. Experimental result demonstrates this model can detect DDoS attack as early as possible with high detection accuracy.

Key words: DDoS attack, correlational packet, flow connection entropy(FCE), non-parametric CUSUM algorithm

中图分类号: