通信学报 ›› 2013, Vol. 34 ›› Issue (Z2): 51-57.doi: 10.3969/j.issn.1000-436x.2013.Z2.011

• 网络与信息安全 • 上一篇    下一篇

基于活跃熵的网络异常流量检测方法

穆祥昆1,2,王劲松1,2,薛羽丰1,2,黄玮1,2   

  1. 1 天津理工大学 智能计算及软件新技术天津市重点实验室,天津 300384
    2 天津理工大学 计算机视觉与系统省部共建教育部重点实验室,天津 300384
  • 出版日期:2013-12-25 发布日期:2017-06-16
  • 基金资助:
    国家自然科学基金资助项目;滨海新区科技小巨人成长计划基金资助项目

Abnormal network traffic detection approach based on alive entropy

Xiang-kun MU1,2,Jin-song WANG1,2,Yu-feng XUE1,2,Wei HUANG1,2   

  1. 1 Tianjin Key Lab of Intelligent Computing &Novel Software Technology,Tianjin University of Technology,Tianjin 300384,China
    2 Key Laboratory of Computer Vision and System,Ministry of Education,Tianjin University of Technology,Tianjin 300384,China
  • Online:2013-12-25 Published:2017-06-16
  • Supported by:
    The National Natural Science Foundation of China;BinHai New District Little Giant of Science and Technology Project

摘要:

提出了一种基于活跃熵的网络异常流量检测新方法,将受监控的目标网络视为一个整体系统,对进出系统的网络数据流所形成的NetFlow记录进行分析,分别统计二者的活跃度井计算它们的活跃熵。在进行活跃熵的计算时,根据流量大小选择不同的尺度来降低误报率,从而能更有效地检测网络流量中存在的异常。在实际网络环境下的模拟实验结果表明,与传统检测方案相比,基于活跃熵的网络异常流量检测方法能够更有效地检测出具有随机特征的网络异常流量。

关键词: 活跃熵, 网络流量, 异常流量检测, NetFlow分析

Abstract:

A novel alive entropy-based detection approach was proposed,which detects the abnormal network traffic based on the values of alive entropies.The alive entropies calculated based on the NetFlow data coming from the network traffic of input and output of a whole system,which is essentially a monitored network.In order to decrease false positive rate of abnormal network traffic,different scales are selected to compute the values of alive entropies in different sizes of network traffic.With the low false positive rate of abnormal network traffic,the abnormal network traffic can be effectively detected.Experiments carried out on a real campus network were used to evaluate the effectiveness of the proposed approach.A comparative study illustrates that the proposed approach may easily detect the abnormal network traffic with random characteristics in comparison with some “conventional” approaches reported in the literatures.

Key words: alive entropy, network traffic, abnormal traffic detection, NetFlow analysis