电信科学 ›› 2021, Vol. 37 ›› Issue (11): 17-32.doi: 10.11959/j.issn.1000-0801.2021257

所属专题: 知识图谱

• 研究与开发 • 上一篇    下一篇

DDoS攻击恶意行为知识库构建

刘飞扬, 李坤, 宋飞, 周华春   

  1. 北京交通大学电子信息工程学院,北京 100044
  • 修回日期:2021-11-15 出版日期:2021-11-20 发布日期:2021-11-01
  • 作者简介:刘飞扬(1997− ),男,北京交通大学电子信息工程学院硕士生,主要研究方向为网络安全
    李坤(1997− ),男,北京交通大学电子信息工程学院博士生,主要研究方向为网络安全、智能通信
    宋飞(1983− ),男,北京交通大学电子信息工程学院教授,主要研究方向为信息网络理论及关键技术、信息处理与人工智能
    周华春(1965− ),男,博士,北京交通大学电子信息工程学院教授,主要研究方向为智能通信、移动互联网、网络安全与卫星网络
  • 基金资助:
    国家重点研发计划项目(2018YFA0701604)

Construction of DDoS attacks malicious behavior knowledge base construction

Feiyang LIU, Kun LI, Fei SONG, Huachun ZHOU   

  1. School of Electronic and Information Engineering, Beijing Jiaotong University, Beijing 100044, China
  • Revised:2021-11-15 Online:2021-11-20 Published:2021-11-01
  • Supported by:
    The National Key Research and Development Program of China(2018YFA0701604)

摘要:

针对分布式拒绝服务(distributed denial of service,DDoS)网络攻击知识库研究不足的问题,提出了DDoS攻击恶意行为知识库的构建方法。该知识库基于知识图谱构建,包含恶意流量检测库和网络安全知识库两部分:恶意流量检测库对 DDoS 攻击引发的恶意流量进行检测并分类;网络安全知识库从流量特征和攻击框架对DDoS 攻击恶意行为建模,并对恶意行为进行推理、溯源和反馈。在此基础上基于DDoS 开放威胁信号(DDoS open threat signaling,DOTS)协议搭建分布式知识库,实现分布式节点间的数据传输、DDoS攻击防御与恶意流量缓解功能。实验结果表明,DDoS攻击恶意行为知识库能在多个网关处有效检测和缓解DDoS攻击引发的恶意流量,并具备分布式知识库间的知识更新和推理功能,表现出良好的可扩展性。

关键词: DDoS, 分布式, 知识图谱, 恶意行为知识库

Abstract:

Aiming at the problem of insufficient research on the knowledge base of distributed denial of service (DDoS) network attacks, a method for constructing a knowledge base of DDoS attacks malicious behavior was proposed.The knowledge base was constructed based on the knowledge graph, and contains two parts: a malicious traffic detection database and a network security knowledge base.The malicious traffic detection database detects and classifies malicious traffic caused by DDoS attacks, the network security knowledge base detects DDoS attacks from traffic characteristics and attack frameworks model malicious behaviors, and perform inference, tracing and feedback on malicious behaviors.On this basis, a distributed knowledge base was built based on the DDoS open threat signaling (DOTS) protocol to realize the functions of data transmission between distributed nodes, DDoS attack defense, and malicious traffic mitigation.The experimental results show that the DDoS attack malicious behavior knowledge base can effectively detect and mitigate the malicious traffic caused by DDoS attacks at multiple gateways, and has the knowledge update and reasoning function between the distributed knowledge bases, showing good scalability.

Key words: DDoS, distributed, knowledge graph, malicious behavior knowledge base

中图分类号: 

No Suggested Reading articles found!