作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (18): 130-133. doi: 10.3969/j.issn.1000-3428.2007.18.046

• 网络与通信 • 上一篇    下一篇

基于信息熵的大规模网络流量异常检测

王海龙,杨岳湘   

  1. (国防科学技术大学计算机学院,长沙 410073)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-09-20 发布日期:2007-09-20

Network-wide Traffic Anomaly Detection Based on Entropy

WANG Hai-long, YANG Yue-xiang   

  1. (School of Computer, National University of Defence Technology, Changsha 410073)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-09-20 Published:2007-09-20

摘要: 提出了基于信息熵的大规模网络流量异常检测方法。该方法吸收了子空间方法的思想,并结合了K-means分类方法。以校园网为实验环境,应用基于信息熵的方法实现了网络流量异常检测的全过程。通过实验结果与应用标准子空间方法对测量数据分析结果的对比,证明了基于信息熵的大规模网络流量异常检测有着更高的检测精度。

关键词: 信息熵, 子空间方法, 大规模网络流量, 异常检测

Abstract: This paper presents a new method of network-wide traffic anomaly detection. The method is based on entropy, which absorbs the idea of subspace method and combines K-means clustering method. In experiment environment of campus networks, the process of detecting network traffic anomalies is realized by applying the method based on entropy. Through the comparison of the results from the experiment and standard subspace method analysis of measurement data, it shows that network-wide traffic anomaly detection based on entropy has a higher detection precision.

Key words: entropy, subspace method, network-wide traffic, anomaly detection

中图分类号: