洪水(心理学)
服务拒绝攻击
协方差矩阵
计算机科学
协方差
基质(化学分析)
数学
算法
统计
心理学
材料科学
互联网
万维网
复合材料
心理治疗师
作者
Daniel Yeung,Shuyuan Jin,Xizhao Wang
出处
期刊:IEEE transactions on systems, man, and cybernetics
[Institute of Electrical and Electronics Engineers]
日期:2007-03-01
卷期号:37 (2): 157-169
被引量:72
标识
DOI:10.1109/tsmca.2006.889480
摘要
This paper presents a covariance-matrix modeling and detection approach to detecting various flooding attacks. Based on the investigation of correlativity changes of monitored network features during flooding attacks, this paper employs statistical covariance matrices to build a norm profile of normal activities in information systems and directly utilizes the changes of covariance matrices to detect various flooding attacks. The classification boundary is constrained by a threshold matrix, where each element evaluates the degree to which an observed covariance matrix is different from the norm profile in terms of the changes of correlation between the monitored network features represented by this element. Based on Chebyshev inequality theory, we give a practical (heuristic) approach to determining the threshold matrix. Furthermore, the result matrix obtained in the detection serves as the second-order features to characterize the detected flooding attack. The performance of the approach is examined by detecting Neptune and Smurf attacks-two common distributed Denial-of-Service flooding attacks. The evaluation results show that the detection approach can accurately differentiate the flooding attacks from the normal traffic. Moreover, we demonstrate that the system extracts a stable set of the second-order features for these two flooding attacks
科研通智能强力驱动
Strongly Powered by AbleSci AI