• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2006, Vol. 28 ›› Issue (10): 16-19.

• 论文 • 上一篇    下一篇

多阶段网络攻击模式挖掘研究

汪生 孙乐昌 阎飞   

  • 出版日期:2006-10-01 发布日期:2010-05-20

  • Online:2006-10-01 Published:2010-05-20

摘要:

在对复杂网络攻击行为进行多阶段特性分析的基础上,本文提出了一种由攻击后果逆向回溯挖掘整个攻击统计特征模式的方法及模型。该模型以网络管理系统收集的网络异常 流量为数据源,通过对不同阶段的攻击特征数据进行Granger因果关系检验,可以提取出描述其关联关系的高置信度攻击模式。文中最后采用五种DDoS工具进行实验研究,结果证实了所提方法及模型的可行性。

关键词: 多阶段网络攻击 攻击模式 数据挖掘 网络安全

Abstract:

In this paper we propose a model to mine the statistical attack signature protiles using the method of reverse backtracking from the attack consequences, on the basis of analyzing the multi-stage characteristics of sophisticated network attack behaviors. The model takes the anomaly network traffic col lected by the network manager system as its data source, employs the Granger causality test as its exploratory tool to extract the association among var ious attack stages, and can achieve several attack profiles with high confidence. Finally experiments with five DDoS tools are conducted, and the result s verify the effectiveness of our work.

Key words: multi-stage network attack, attack profile, data mining, network security