DDoS攻击检测模型的设计  

Design of Attacks Detection Model of Distributed Denial of Service

在线阅读下载全文

作  者:胡中功[1] 程思婷 沈斌[1] 陈爱杰[1] 

机构地区:[1]武汉工程大学电气信息学院,湖北武汉430205

出  处:《武汉工程大学学报》2017年第1期91-95,共5页Journal of Wuhan Institute of Technology

摘  要:为了有效检测服务器是否受到DDoS攻击,设计了一种基于朴素贝叶斯分类算法的DDoS攻击检测模型.首先大量抓取服务器数据包,选择受到DDoS攻击时产生较明显变动的5种特征数据作为基本参数,所有数据可分为受攻击与未受攻击两类.然后利用正态分布函数拟各合特征量的分布情况,并计算出各个特征量的条件概率.最后,选取测试数据,得到测试数据在贝叶斯公式下被分为受攻击与未受攻击两类的后验概率,并通过比较此两个后验概率值的大小,判断出服务器是否受到DDoS攻击.该模型经MATLAB仿真实验的验证,获得了较高的准确率,保证了对DDoS攻击的有效检测,并由C++代码进行实现.To effectively detect whether the server was attacked by distributed denial of service(DDoS),we designed a DDoS attacks detection model based on the naive Bias classification algorithm. Firstly,five kinds of data with obviously changed characteristic in DDoS attacks,which were obtained from the large number of server data packets,were chosen as the basic parameters and divided into two categories of being attacked or not. Then,the conditional probability of each characteristic was calculated by using normal distribution function to fit the characteristic parameters. Finally,whether the server was attacked or not by DDoS was judged by comparing the two posterior probabilities of the selected test data based on the Bayesian formula. The model established by C++code ensures the effective detection of DDoS attacks with higher accuracy via the MATLAB simulation experiments.

关 键 词:DDOS攻击 朴素贝叶斯分类算法 特征数据 正态分布函数 检测模型 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象