基于特征融合相似度的域间路由系统安全威胁感知方法

来源 :中国科学:信息科学 | 被引量 : 0次 | 上传用户:bravehearterdoctor
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
针对域间路由系统的网络攻击技术日益复杂,尤其是近年出现的基于大规模LDo S(low-rate denial of service)的跨平面攻击,其造成的危害远大于传统网络攻击.已有域间路由系统安全技术主要研究如何解决BGP(border gateway protocol)协议缺乏路由真实性验证机制的问题,而针对域间路由系统的大规模LDo S攻击利用的是BGP协议自适应机制的特性,且用于LDo S攻击的流量与许多真实数据流的特征类似,使得现有很多方法难以有效应对.本文提出一种基于加权相似度的域间路由系统安全威胁感知方法,利用多个特征融合描述域间路由系统的安全状态,并结合网络流量的自相似特性,运用加权相似度计算方法量化实时特征值与正常态特征值的偏差,由此评估域间路由系统的安全状态.进一步,通过跟踪安全特征的实时变化情况,即可推断域间路由系统遭受攻击的类型.实验结果表明,该方法能够实现对域间路由系统安全状态的有效评估,在遭受控制平面攻击或数据平面攻击的初期阶段即能感知威胁,为网络管理员及时制定有效的应对策略提供可靠参考. Inter-domain routing system for network attack technology is increasingly complex, especially in recent years, based on large-scale LDoS (cross-plane denial of service) cross-plane attacks, the harm caused by far greater than the traditional network attacks. The system security technology mainly studies how to solve the problem that the border gateway protocol (BGP) lacks the route authenticity verification mechanism, and the large-scale LDoS attack against the inter-domain routing system uses the characteristic of the BGP protocol adaptation mechanism and is used for LDo S attack traffic is similar to the features of many real data flows, which makes many existing methods difficult to deal with effectively.This paper proposes a method based on weighted similarity to detect the security threat of inter-domain routing system, using multiple feature fusion to describe the inter-domain routing system , And combined with the self-similar characteristics of network traffic, the weighted similarity calculation method is used to quantify the deviation of the real-time eigenvalues ​​from the normal eigenvalues ​​to evaluate the security status of the inter-domain routing system.Furthermore, by tracking the real-time We can deduce the types of attacked inter-domain routing system.The experimental results show that this method can Effective evaluation of the inter-domain routing system security status, suffered in the early stages of the control plane and data plane attacks that can attack perceived threats, network administrators to develop effective coping strategies to provide a reliable reference.
其他文献
利用北京—丰镇及其邻区三分向宽角反射/折射DSS剖面(总长340.0km)所获信息和利用数字处理技术,充分识别、提取了地壳和上地幔顶部的多种S波折射、反射震相(波组).结合P波解释结果,计算了包括S波速
在2012年11月22日举行的遵义市红花岗区“优化课堂教学”青年教师展示课活交中,我执教了人教版二年级上册第22课《窗前的气球》。这篇课文以科利亚的情感变化为线索,讲述了科
It is reported from Tiandilong Group that its 250,000-ton 8mm copper rod production line is scheduled to put into production this May. It is It is reported fro
颅底孔道的高分辨力CT研究魏文洲①章志霖郑小华林怡蔼本文采用薄层高分辨力CT(highresolutionCT)放大重建技术对50例正常成人颅底孔道进行了研究,旨在明确中国人颅底孔道的正常径值和形态,为判断病变提
1997年11月份本市发生一起重大火灾,直接经济损失47.3万元。11月4日2时30分,嘉定区戬洪镇大冶路343号上海宝马鞋业有限公司发生重大火灾。由于11月311晚8时许工人在成型车间由南
CD3AK细胞是由小剂量CD3单抗交联CD3分子活化的T型淋巴细胞,其细胞激活及产量显著提高,且在增殖速度、激活频率等方面优于 LAK细胞[1]。近期发现 CD3AK细胞不仅可直接杀伤靶
Background &Aims: Liver transplant recipients infected with hepatitis C virus (HCV) develop recurrent hepatitis soon after transplantation and, in some cases, p
患者,男,23岁,5年前无诱因突感脐周绞痛,犹如内脏翻滚,继之面色苍白,烦躁、恶心、呕吐,无抽搐及意识障碍。去某医院按“急性胃肠炎”诊治,经消炎、解痉止痛,1小时后疼痛缓解。此后每20
今年七月中旬,党中央、国务院召开了全国打击走私工作会议,江泽民总书记、朱基总理出席会议并作了重要讲话。江泽民指出,日益猖獗的走私活动,不仅直接冲击和扰乱市场秩序,危害民族
Background: Tegaserod, a prokinetic 5-HT4 receptor agonist, has demonstrated efficacy and tolerability in irritable bowel syndrome (IBS) patients with constipat