作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2018, Vol. 44 ›› Issue (10): 14-21. doi: 10.19678/j.issn.1000-3428.0051296

所属专题: 网络空间安全专题

• 网络空间安全专题 • 上一篇    下一篇

基于IPv6的大规模网络异常流量检测系统设计

王劲松1,2,3李军燕1,2,3,张洪玮1,2,3,宫良一1,2,3   

  1. 1.天津理工大学 计算机科学与工程学院,天津 300384; 2.天津市智能计算及软件新技术重点实验室,天津 300384; 3.计算机病毒防治技术国家工程实验室,天津 300457
  • 收稿日期:2018-04-23 出版日期:2018-10-15 发布日期:2018-10-15
  • 作者简介:王劲松(1970—),男,研究员、博士,主研方向为网络安全;李军燕,本科生;张洪玮,博士研究生;宫良一,讲师、博士。
  • 基金资助:

    国家自然科学基金(61272450);天津市大学生创新创业项目(201610060032);赛尔网络下一代互联网技术创新项目(NGII20150410)。

Design of Large-scale Network Anomaly Traffic Detection System Based on IPv6

WANG Jinsong1,2,3,LI Junyan1,2,3,ZHANG Hongwei1,2,3,GONG Liangyi1,2,3#br#   

  1. 1.School of Computer Science and Engineering,Tianjin University of Technology,Tianjin 300384,China; 2.Tianjin Key Laboratory of Intelligence Computing and Novel Software Technology,Tianjin 300384,China; 3.National Engineering Laboratory for Computer Virus Prevention and Control Technology,Tianjin 300457,China
  • Received:2018-04-23 Online:2018-10-15 Published:2018-10-15

摘要:

随着IPv4地址濒临枯竭,国内网络由IPv4已逐渐转向IPv6,使得基于IPv6的大规模网络流量急剧扩大,IPv6网络面临的安全风险与攻击威胁成为网络发展亟待解决的问题。为此,在实际IPv6网络环境中,通过实时获取各处理大规模网络中的IPv6流量,进行流量分类与异常流量常规检测,提出基于滑动时间窗的k_means网络异常检测算法。设计基于IPv6协议的网络异常流量检测系统,分析系统性能并进行测试。实验结果表明,该算法能够有效检测出网络中的异常流量,并为基于IPv6网络流量的后续研究与异常检测工作提供良好的实验平台。

关键词: IPv6协议, 大数据, K-means算法, 滑动时间窗, 异常流量检测

Abstract:

With the exhaustion of IPv4 addresses,the domestic network has gradually shifts to IPv6 from IPv4,which leads to the rapid expansion of large-scale network traffic based on IPv6.The security risks and attack threats faced by IPv6 networks becomes an urgent problem to be solved in network development.Therefore,in the actual IPv6 network environment,the real-time acquisition of large-scale IPv6 data traffic based on IPv6 dual protocol stack is studied,and traffic classification and anofmaly traffic routine detection are carried out.The k_means network anomaly detection algorithm based on sliding time window is proposed.It designs a network abnormal traffic detection system based on IPv6 protocol,analyzes system performance and gives test results.Experimental results show that the algorithm can effectively detect anomaly traffic in the network and provide a good experimental platform for subsequent research and anomaly detection based on IPv6 network traffic.

Key words: IPv6 protocol, big data, K-means algorithm, sliding time window, anomaly traffic detection

中图分类号: