Dissertation > Excellent graduate degree dissertation topics show
Anomaly Traffic Detection Research and Implementation Base on Netflow
Author: TianYang
Tutor: ChenXiaoMei
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Priori algorithm Posteriori algorithm PBP algorithm NBD algorithm Anomaly Detection
CLC: TP393.06
Type: Master's thesis
Year: 2009
Downloads: 46
Quote: 1
Read: Download Dissertation
Abstract
|
With the development of Internet technology, the network structure is more and more complex, cross-penetration network environment, network applications are increasingly diverse. Network traffic anomaly due to a variety of causes, will not only reduce the network performance, consuming network resources, what is more likely to lead to a service provider can not operate normally, lead to loss of business, network hardware facilities paralysis, causing huge economic losses. So accurate and fast positioning time and space of the network abnormal flow position to identify the network abnormal flows of network operators, network users are of great significance. Network anomaly detection algorithm is the key to quickly locate network abnormal flow. Papers to the learning process, based on the need for historical inspection data network anomaly detection algorithm is divided into a priori two types of algorithms and a posteriori algorithm, and designed and implemented a K-Means, PCA, information entropy decision tree, Naive Bayes based five typical flow characteristics of the anomaly detection algorithm. Based on the basis of the experimental analysis of the existing algorithms, the paper proposed based on Bayesian decision theory based on a priori triggered improved BP neural network algorithm (Priori triggered BP neural network algorithm, referred to as PBP) algorithm (Na? Ve of Bayes Decision theory, referred NBD). Not adaptive learning algorithm for the posterior priori algorithm detection accuracy is low, big error, PBP algorithm uses the K-Means and PCA algorithm to trigger adaptive learning process, the use of historical layers of neurons the parameters average of initialization nerve network, learn good network anomaly detection. Experimental results show that the the PBP algorithm can obtain a high detection accuracy of the ratio priori algorithm according to the network environment, and can adaptive learning. PBP algorithm to learn a long time, the problem of slow convergence, NBD algorithm using risk assessment and error analysis of to trigger adaptive learning process, learning good Bayesian probability network anomaly detection to speed up the reaction time of the anomaly detection to ensure a high-precision, low false positive rate and low false negative rate. The experimental results show that the NBD algorithm can achieve high detection accuracy than the a priori algorithm, and does not depend on the network structure, the learning time is short, fast convergence rate applicable to the detection of abnormal flow in most network environments. Paper based Netflow traffic data based on anomaly detection system. Formation flow initial vector set the system to obtain real-time traffic data Netflow, after pretreatment, and then use the five classical algorithm we propose PBP NBD algorithm for anomaly detection. Last experimental test of the system in the campus network. The test results show that the system has better real-time detection effect, there are certain practical value.
|
Related Dissertations
- Research on Network Anomaly Detection Based on Projection Pursuit Regression,TP393.08
- Research on the Detection Model of Anomaly Network Traffic,TP393.08
- Sequence inherent mode theory and application,TP311.13
- Researches on Propagation Model of Computer Viruses and Technology of Defense,TP309.5
- Based on packet sampling anomaly detection in high-speed network intrusion detection system research,TP393.08
- Anomaly Detection Model of Clinical Sequences,R197.324
- MIB -based large-scale network anomaly detection node,TN915.06
- Intrusion Detection Based on Clustering Algorithm and Implementation,TP393.08
- Unsupervised anomaly detection technology research and application,TP393.08
- Detector method of generating and self- representation,TP309
- Botnet Anomaly Detecion,TP393.08
- Research on Frequency Analysis-based Network Traffic Anomaly Detection,TP393.06
- IPv6-based combined misuse and anomaly intrusion detection system research and design,TP393.08
- The Study of Fast Network Traffic Anomaly Detection Based on Iteration,TP393.08
- Wireless Sensor Network Intrusion Detection Method Analysis and Research,TN918.82
- Research on Trust Mechanism for P2P Networks,TP393.08
- Virtual accounting the time flights abnormal delay Behavior,F562
- Detecting and Analysing Traffic Anomalies at Application Layer in Metro Area Network,TP393.1
- Based on Catastrophe Theory IP network abnormal behavior detection and control mechanisms,TP393.08
- Data Mining in Intrusion Detection System Research,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer networks, test , run
© 2012 www.DissertationTopic.Net Mobile
|