基于马尔科夫的计算机网络缓存侧信道攻击检测方法  

Markov⁃Based Detection Method for Cache⁃Side Channel Attack in Computer Networks

在线阅读下载全文

作  者:黄丽芳[1] HUANG Lifang(School of Information Management,Minnan University of Science and Technology,Shishi Fujian 362700,China)

机构地区:[1]闽南理工学院信息管理学院,福建石狮362700

出  处:《海南热带海洋学院学报》2024年第5期104-110,118,共8页Journal of Hainan Tropical Ocean University

基  金:闽南理工学院科技创新团队项目(23XTD114)。

摘  要:计算机网络缓存侧信道能够间接体现计算机内部状态以及数据传输情况,其受攻击时,用户端信息数据存在泄露风险,因此提出一种基于马尔科夫的计算机网络缓存侧信道攻击检测方法。构建隐马尔科夫模型,对计算机网络缓存侧信道状态改变的概率进行计算。通过Baum‐Welch算法估计隐马尔科夫模型最优参数,并计算缓存侧信道状态观测序列输出概率。比较缓存侧信道观测序列输出概率与设定的阈值,判断该序列为计算机网络缓存侧信道攻击信号的可能性,并引入平均信息熵判断计算机缓存侧信道状态是否存在异常,完成计算机网络缓存侧信道攻击检测。通过实验验证得出,该方法用于计算机网络缓存侧信道攻击检测的准确率高,误报率低,在遭受DDoS攻击(Distributed denial of service)时的检测时间较短,对计算机网络缓存侧信道攻击的防御与保护产生了积极影响。As the computer network cache side channel indirectly reflects the internal state and data transmission situation of the computer,there is a risk of leakage of user‐side information data when it is attacked.Therefore,a Markovbased detection method for computer network cache side channel attack was proposed.A hidden Markov model was constructed to calculate the probability of channel state changes on the cache side of the computer network.The optimal parameters of the hidden Markov model were estimated by Baum Welch algorithm,and the output probability of the channel state observation sequence on the cache side was calculated.Comparing the output probability of the cache side channel observation sequence with the set threshold,the possibility of the sequence being a computer network cache side channel attack signal was determined.Meanwhile,the average information entropy was employed to determine any abnormality in the computer cache side channel state,to complete the detection of computer network cache side channel attacks.Through experimental verification,it was found that the present method has high accuracy and low false alarm rate when employed in computer network cache side channel attack detection,and a short detection time when subjected to DDoS attacks(Distributed Denial of Service).The method exerts a positive impact on the defense and protection of cache side channel attacks in computer networks.

关 键 词:计算机网络 信道攻击检测 缓存侧 隐马尔科夫模型 Baum-Welch算法 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象