论文部分内容阅读
针对日益严重的拒绝服务(DoS)网络攻击行为,提出了一种基于活跃熵的DoS攻击检测模型。该模型通过活跃通信理论将信息熵与网络流会话相关性结合起来,通过分析网络流量活跃熵值的变化实现对DoS攻击行为的检测。实验结果表明:正常网络流量下活跃熵值基本稳定,在发生DoS攻击时网络流量的活跃熵值波动明显;该模型与静态熵检测模型相比,检测结果更准确,同时能够更有效地检测未知的DoS攻击行为。
Aiming at the increasingly serious Denial of Service (DoS) network attacks, a DoS attack detection model based on active entropy is proposed. The model combines the information entropy with the relevance of network streaming sessions through active communication theory, and detects the DoS attacks by analyzing the changes of active entropy of network traffic. The experimental results show that the active entropy under normal network traffic is basically stable, and the active entropy of network traffic fluctuates significantly when DoS attack occurs. Compared with the static entropy detection model, the detection result is more accurate and the unknown entropy can be more effectively detected DoS attacks.