首页 | 官方网站   微博 | 高级检索  
     

基于多维时间序列分析的网络异常检测
引用本文:陈兴蜀,江天宇,曾雪梅,尹学渊,邵国林.基于多维时间序列分析的网络异常检测[J].四川大学学报(工程科学版),2017,49(1):144-150.
作者姓名:陈兴蜀  江天宇  曾雪梅  尹学渊  邵国林
作者单位:四川大学 网络空间安全研究院, 四川 成都 610065;四川大学 计算机学院, 四川 成都 610065;四川大学 网络空间安全研究院, 四川 成都 610065;四川大学 计算机学院, 四川 成都 610065;四川大学 计算机学院, 四川 成都 610065
基金项目:国家自然科学基金资助项目(61272447)
摘    要:针对实际网络异常检测要求高检测率、低误报率的问题,提出了一种基于多维时间序列的检测方法。首先,通过对实际网络流量进行长期观测,提取多维特征对网络流量进行描述;然后,利用时间序列分析方法对多维特征进行预测,计算预测值与真实值的时间序列偏离度,并且实时更新偏离度,适应多变的网络环境;最后,利用支持向量机(SVM)算法对偏离度向量进行分类判别,判断是否发生异常。目前该方法已应用于校园网关键服务器的实时监测与防护工作中,实际服务器流量的预测、告警结果表明,该方法可以有效检测网络中的异常流量。

关 键 词:异常检测  时间序列  网络流量  多维特征  网络安全
收稿时间:2016/9/18 0:00:00
修稿时间:2016/11/1 0:00:00

Network Anomaly Detector Based on Multiple Time Series Analysis
CHEN Xingshu,JIANG Tianyu,ZENG Xuemei,YIN Xueyuan and SHAO Guolin.Network Anomaly Detector Based on Multiple Time Series Analysis[J].Journal of Sichuan University (Engineering Science Edition),2017,49(1):144-150.
Authors:CHEN Xingshu  JIANG Tianyu  ZENG Xuemei  YIN Xueyuan and SHAO Guolin
Affiliation:Cybersecurity Research Inst., Sichuan Univ., Chengdu 610065, China;College of Computer Sci., Sichuan Univ., Chengdu 610065, China;Cybersecurity Research Inst., Sichuan Univ., Chengdu 610065, China;College of Computer Sci., Sichuan Univ., Chengdu 610065, China;College of Computer Sci., Sichuan Univ., Chengdu 610065, China
Abstract:The anomaly detection of network traffic in practice requires both high detection rate and low false alarm rate.To address this problem,a detection approach based on multidimensional time series analysis was proposed.Firstly,the network traffic was observed in a long time,and multiple network features were chosen for building the network behavior model.Subsequently,multiple features were predicted by the method of time series analysis.Then the degree of deviation between the predict value and the real value was calculated and updated.Finally,the state of whether the network flow is normal was determined by using support vector machine to classify the degree of deviation in time series.This method has been applied to real-time monitoring and protection on a campus key server.The results showed that it can detect anomalies effectively in network traffic.
Keywords:anomaly detection  time series  network traffic  multiple features  network security
点击此处可从《四川大学学报(工程科学版)》浏览原始摘要信息
点击此处可从《四川大学学报(工程科学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号