检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:陈治昊 CHEN Zhihao(College of Cybersecurity,Sichuan University,Chengdu 610065)
出 处:《现代计算机》2021年第17期106-113,共8页Modern Computer
摘 要:为了解决传统DNS隧道攻击检测方法因大量会话重组导致检测效率不高的问题,提出一种多粒度DNS隧道攻击检测方法,该方法采用粗细粒度相结合的方式对DNS隧道攻击行为进行分析,通过将DNS会话划分时间片提取粗粒度特征,减少会话重组与特征提取的时间,并在异常时间片上重组会话后提取更多细粒度特征加以分析,准确定位隧道攻击流量。最后通过实验结果验证多粒度DNS隧道攻击检测方法在保持检测准确率的同时明显提升检测效率。Regarding the low detection efficiency problem in the traditional DNS tunneling attack detection method caused by the process of session reorganization,a multi-granularity DNS tunneling attack detection method was proposed,which uses the combination of coarse and fine granularity to analyze DNS tunneling attack. By dividing DNS session into time slices to extract coarse-grained features,we can reduce the time of session reorganization and feature extraction,and extract a variety of fine-grained features after session reorganization on abnormal time slices for analysis,so as to accurately locate the traffic of tunnel session. The experimental results show that the multi-granularity DNS tunneling attack detection method improves the detection efficiency while maintaining the detection accuracy.
关 键 词:DNS隧道攻击 行为分析 多粒度分析 BIRCH算法 入侵检测
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.185