作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (6): 116-118. doi: 10.3969/j.issn.1000-3428.2009.06.040

• 网络与通信 • 上一篇    下一篇

基于特征分布分析的网络流量监测系统

杜 鑫,杨英杰,常德显   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-03-20 发布日期:2009-03-20

Network Traffic Supervision System Based on Feature Distribution Analysis

DU Xin, YANG Ying-jie, CHANG De-xian   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004)

  • Received:1900-01-01 Revised:1900-01-01 Online:2009-03-20 Published:2009-03-20

摘要: 多数现有网络流量监测系统只关注流量大小,没有分析流量内部信息。该文利用熵来衡量源IP地址、目的IP地址、目的端口等流量特征参数的分布变化,从特征分布的角度对网络流量进行分析。采用该方法实现一个流量监测系统,实验结果证明,该系统具有较高检测率和较低误报率。

关键词: 流量监测, 特征分布,

Abstract: Most existing network traffic supervision systems focus on the volume of traffic, and do not analyze information contained in these data. This paper utilizes entropy to capture the change of network traffic feature distribution, such as source IP address, target IP address, target port, and analyzes network traffic from the standpoint of feature distribution. It implements a supervision system by using this method. Experimental results show that this system has a higher detecting rate and a lower fault rate.

Key words: traffic supervision, feature distribution, entropy

中图分类号: