Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Low-speed denial of service attack detection method based on cloud model

A denial of service attack and detection method technology, applied in electrical components, transmission systems, etc., can solve problems such as reduced detection performance, and achieve the effects of fewer samples, good detection accuracy, low false positive rate and false negative rate.

Inactive Publication Date: 2019-03-08
HUNAN UNIV
View PDF6 Cites 8 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] Aiming at the problem of detection performance degradation caused by network traffic uncertainty in the existing detection algorithm, the present invention proposes a cloud model-based low-speed denial-of-service attack detection method based on the cloud model theory

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Low-speed denial of service attack detection method based on cloud model
  • Low-speed denial of service attack detection method based on cloud model
  • Low-speed denial of service attack detection method based on cloud model

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0022] The present invention will be further described below in conjunction with accompanying drawing.

[0023] Such as figure 1 As shown, when a low-speed denial-of-service attack occurs, the cloud model form of TCP traffic data is quite different from that of the other two states. Wider and thicker, the shape of the cloud model under other attacks is narrower and thinner, and the cloud model coordinates of the low-speed denial of service attack and other attacks are more left than the cloud model without attack.

[0024] Such as figure 2 As shown, under the low-speed denial-of-service attack, the expectation in the numerical feature group C(Ex, En, He) of the cloud model is different from that in the other two states. There is a certain degree of decline, which is different from the non-attack state. This is the basis for detecting low-speed denial-of-service attacks, and further constructs an attack detection classifier.

[0025] Such as image 3 As shown, under the lo...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a low-speed denial of service attack detection method based on a cloud model and belongs to the field of computer network security. The method comprises four steps of collecting samples, extracting features, establishing an attack detection classifier and carrying out judgment and detection. Sample collection points are set in a bottleneck link; network traffic data is collected; TCP traffic data is extracted from the network traffic data; network traffic is analyzed through utilization of a cloud model theory which can avoid an establishment error resulting from network traffic uncertainty; TCP traffic in the bottleneck link is analyzed through adoption of a reverse cloud generation algorithm, thereby obtaining a numeric feature group; the attack detection classifier is established through utilization of a support vector machine with small sample learning capacity; and output of the attack detection classifier is taken as basis, and whether a low-speed denial of service attack occurs or not is judged. According to the low-speed denial of service attack detection method provided by the invention, the required number of samples is low, and relatively low false alarm rate and missing report rate are realized.

Description

technical field [0001] The invention relates to the field of computer network security, in particular to a low-speed denial-of-service attack detection method based on a cloud model. Background technique [0002] Low-speed denial-of-service attack is one of the variants of denial-of-service attack. It mainly uses the TCP / IP congestion control mechanism to periodically send high-rate short-pulse attack streams to the target user, causing the network to be in a state of false congestion, and the quality of service is seriously reduced. . This new type of denial-of-service attack has a low average rate and good concealment, and the traditional denial-of-service attack detection method is difficult to work. [0003] The existing low-speed denial-of-service attack detection methods are divided into two categories according to the detection objects: the low-speed denial-of-service attack detection method based on router queue analysis and the low-speed denial-of-service attack de...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/1416H04L63/1458
Inventor 汤澹詹思佳施玮满坚平代锐郑凯吴小雪张斯琦
Owner HUNAN UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products