科技通报
科技通報
과기통보
BULLETIN OF SCIENCE AND TECHNOLOGY
2014年
2期
127-129
,共3页
通信痕迹%网络危险%分区
通信痕跡%網絡危險%分區
통신흔적%망락위험%분구
communication mark%network danger%partition
当前的网络攻击检测都没有充分考虑攻击的直接联系性,对攻击内在的直接关联缺少关注,导致攻击分类和网络威胁分区的准确性不高。为了解决这一问题,提出一种基于通信痕迹的网络威胁分区方法。通过提取网络威胁内在特有的主成份特征,构建出上一次攻击留下的通信痕迹,根据通信痕迹的反馈对本次攻击进行分区,保证同区域内的攻击特征类似,为后期的攻击图谱构建打下基础。计算机仿真实验证明,该方法可以很好的解决网络威胁检测缺少关联性的弊端,提高了入侵检测的准确度。
噹前的網絡攻擊檢測都沒有充分攷慮攻擊的直接聯繫性,對攻擊內在的直接關聯缺少關註,導緻攻擊分類和網絡威脅分區的準確性不高。為瞭解決這一問題,提齣一種基于通信痕跡的網絡威脅分區方法。通過提取網絡威脅內在特有的主成份特徵,構建齣上一次攻擊留下的通信痕跡,根據通信痕跡的反饋對本次攻擊進行分區,保證同區域內的攻擊特徵類似,為後期的攻擊圖譜構建打下基礎。計算機倣真實驗證明,該方法可以很好的解決網絡威脅檢測缺少關聯性的弊耑,提高瞭入侵檢測的準確度。
당전적망락공격검측도몰유충분고필공격적직접련계성,대공격내재적직접관련결소관주,도치공격분류화망락위협분구적준학성불고。위료해결저일문제,제출일충기우통신흔적적망락위협분구방법。통과제취망락위협내재특유적주성빈특정,구건출상일차공격류하적통신흔적,근거통신흔적적반궤대본차공격진행분구,보증동구역내적공격특정유사,위후기적공격도보구건타하기출。계산궤방진실험증명,해방법가이흔호적해결망락위협검측결소관련성적폐단,제고료입침검측적준학도。
The current network attack detection, are not fully considered directly attack item that the lack of direct attack the intrinsic connection between attention, lead to the classification of network attacks and threats partition accuracy is not high. In order to solve this problem, this paper puts forward a trace based on communication network threat partition method. Through the extraction network threat intrinsic characteristic of principal component characteristics, constructing the last attack left traces of communication, according to the communication traces of this feedback attack partitions, guarantee in the areas with similar attack characteristics, for later attack map construction to lay the foundation. The computer simulation proved that change method can well solve the network to threat the disadvantages of lack of correla-tion detection and improve the intrusion detection accuracy.