Dissertation > Excellent graduate degree dissertation topics show
Based on the correlation matrix of the network abnormal behavior analysis method
Author: ChenYu
Tutor: WuYongYing
School: Huazhong University of Science and Technology
Course: Computer System Architecture
Keywords: Network Anomaly Anomaly analysis Network Scanning Denial of Service Attack Correlation matrix Time granularity
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 50
Quote: 0
Read: Download Dissertation
Abstract
|
Current network , there are many , such as network scanning , denial of service attacks or network to network intrusion damage for the purpose of network abnormal behavior , seriously affecting the normal operation of the network . Although there is now a threshold -based filtering , feature matching , statistical testing and other network anomaly detection methods, but these methods are primarily focused on the discovery of network anomalies and how to achieve protection, ignoring the anomalies found necessary in-depth analysis . Therefore, the paper proposes a method of network anomaly analysis has important theoretical significance and practical value. Discusses the analysis of network anomaly of the technology involved and related concepts . From the TCP (Transmission Control Protocol) connection establishment and connection to start dismantling the integrity of the message , select the five TCP packet analysis of network anomalies as the cause of the observed packets are given ideal conditions between the TCP packet number five on the relationship , focusing on analysis of the existing network common network abnormal behavior , such as network scanning , denial of service attacks. Explains how to use the correlation matrix to represent the TCP packet stream many types of close correlation between the degree and five under normal conditions established TCP packet correlation criterion . Given based on the correlation matrix network anomaly behavior analysis method of the basic ideas , information was given time granularity , the number of samples on the impact of the correlation coefficient calculation results are analyzed abnormal behavior common TCP flow correlation matrix calculation results on the impact of . Experimental results show that the correlation matrix based network anomaly behavior analysis method can be more accurately distinguish TCP Maimon scan , DDoS (Distributed Denial of Service) attacks and other network abnormal behavior , has a certain practical value.
|
Related Dissertations
- Implementation and Research of Illegal Websites Detection System Based on Comparison Methods,TP393.08
- Research on Network Anomaly Detection Based on Projection Pursuit Regression,TP393.08
- Complex fault tree qualitative and quantitative analysis of algorithm research and application,X913.4
- Key Technologies Research and Practice on Network Intrusion Detection System,TP393.08
- Security Analysis and Research about the Icmp,TP393.08
- The Model of Cooperation and Compensation for Dealing with River Network Pollutants Based on the Cost Function,O242.1
- Research on the System of Network Topology and Terminal Access Status,TP393.02
- Research on Configuration Management of Gas Insulated Switchgear for Mass Customization,TM595
- The Research on the Modularization Based on the CXT Series Electrical Hoist,TH211.3
- IP Traceback Technology and Its Application to Defense of DDoS Attack,TP393.08
- Study on Array Calibration and Direct Wave Suppression for High Frequency Hybrid Sky-Surface Wave Radar,TN958.93
- Research on Ionospheric Contamination Mitigation Algorithm for High Frequency Sky-wave Radar,TN958.93
- Urban Noise island model and its application in the noise monitoring sites Optimization,TP274
- The Research of 2D Parameters Super-resolution Estimation on UCA in Non-ideal Environment,TN911.23
- DDoS attacks based on packet marking defensive secondary methods of adaptation,TP393.08
- Network security event monitoring system to monitor subsystem design and implementation,TP393.08
- Research on Probabilistic Packet Marking Based Intrusion Traceback Technology,TP393.08
- Against denial of service attacks Active Queue Management Algorithm,TP393.08
- Analysis of DDoS attack and defense research,TP393.08
- Low technology denial of service attacks,TP393.08
- Network security scanner in the design and implementation of Web crawler,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|