作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (12): 167-169. doi: 10.3969/j.issn.1000-3428.2010.12.057

• 安全技术 • 上一篇    下一篇

基于行为模式挖掘的骨干网攻击检测算法

王红兵   

  1. (国家计算机网络应急技术处理协调中心,北京 100029)
  • 出版日期:2010-06-20 发布日期:2010-06-20
  • 作者简介:王红兵(1966-),女,高级工程师、硕士,主研方向:网络安全检测,信息安全

Backbone Network Attack Detection Algorithm Based on Behavior Pattern Mining

WANG Hong-bing   

  1. (National Computer Network Emergency Response Technical Team/Coordination Center of China, Beijing 100029)
  • Online:2010-06-20 Published:2010-06-20

摘要: 针对Internet骨干网面临的主要攻击行为,提出一种基于攻击行为模式的建模方法。基于行为模式挖掘设计一种快速检测算法,提出一种基于双页表结构的攻击信息树的构建算法。实验结果证明该检测方法能够实时地检测骨干网中已知或未知的攻击,定位报告受害源。

关键词: 攻击检测, 关系模型, 模式挖掘

Abstract: According to the attacks in Internet backbone network, this paper proposes a modeling method based on attack behavior model, including devising a fast algorithm based on behavior pattern mining, and puts forward a 2-page hash table attack tree algorithm. Experimental results confirm that the algorithm can detect known or unknown threats effectively and has the ability to report the suspicious address.

Key words: attack detection, relation model, pattern mining

中图分类号: