Dissertation > Excellent graduate degree dissertation topics show
Network Anomaly Detection Based on Statistical Approach and Time Series Analysis
Author: HuangZuo
Tutor: LiangALei
School: Shanghai Jiaotong University
Course: Software Engineering
Keywords: Network Anomaly Detection Expectation Maximization algorithm Gaussian mixture model K D indicator approach Smooth Moving Average Convergence Divergence Timing Analysis
CLC: TP393.06
Type: Master's thesis
Year: 2009
Downloads: 103
Quote: 0
Read: Download Dissertation
Abstract
|
Network frequently router transmission rate changes , the device restart worm attack , abnormal fluctuations . Network anomalies as soon as possible to avoid the occurrence of serious problems in the future and the rapid recovery of the disaster to play a crucial role . This has provided a guarantee to provide a stable network transmission . In this paper , we use statistical methods to analyze the distribution of network traffic to identify network traffic under normal circumstances . However , the traffic of different protocols have different statistical characteristics . Not a single distribution to match the distribution of network traffic . A lot of research work has been the basis for this conclusion . We experiment through the analysis of the actual data to verify this assertion . We adopt the expectation maximization algorithm to estimate the distribution of the Gaussian mixture model parameters widely used in the field of artificial intelligence . Once the statistical feature abnormal fluctuations or sudden changes of the network traffic , and exceeds a certain threshold alarm will be triggered. We use the time series analysis methods to deal with the results of statistical analysis of data . In the first method , determined by analysis of the upper and lower bounds . If the parameter is out of the upper and lower bounds on the judgment for an exception occurs . Another time series analysis method called by two K D index line staggered to reflect abnormal fluctuations in the network . Portrayed two indicator lines are similar to the mean of the historical data . The one for which the latest data volatility is more sensitive , while the other one is more dull . The third method is the MACD indicator line . Such methods and K, D method is very similar to , but is relatively less sensitive to volatility . Through experiments we found that abnormal judgment but more correct . Our experiment eventually proved the effectiveness of the method .
|
Related Dissertations
- Detection and Tracking of Moving Object in Complex Background,TP391.41
- Research on Network Anomaly Detection Based on Projection Pursuit Regression,TP393.08
- Key Algorithm in High Quality Voice Conversion System,TN912.3
- Research of Moving Object Detection and Tracking Technology,TP391.41
- Image Spam Detecting Based on Combinatorial and Statistical Classifier,TP391.41
- Multi-feature fusion of visual tracking algorithm,TP391.41
- Video surveillance system moving target detection algorithm,TP391.41
- High water on the open pit slope stability study effects,TD804
- Embedded target detection and tracking system design and algorithm implementation,TP391.41
- GPU-based acceleration techniques EDA,TP391.41
- The Research and Implementation of Target Tracking Algorithm Based on Mean-shift and Particle Filter,TP391.41
- Distributed sound source localization and tracking algorithm,TN912.3
- Research on Pursuer-Evader Tracking Problem Using WSN,TP212.9
- Research on the Key Technologies of Intelligent Transportation Video Surveillance System,TP391.41
- Border defense system moving target tracking technology Research and Implementation,TP391.41
- Design and Implementation of a DSP Modeling and Timing Analysis Tool,TP368.1
- A Design of Post Placement and Routing Simulation Based on FPGA,TN791
- The Study and Implementation of Timing Modeling Techniques for Full-Custom Macro Blocks,TN47
- The Application of Gaussian Mixture Model in the Detection of Community Structure of Networks,TP393.094
- Study and Implement on Key Technology of Human Motion Detection and Abnormal Behavior Recognition,TP391.41
- Target recognition based on computer vision technology R \u0026 D,TP391.41
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer networks, test , run
© 2012 www.DissertationTopic.Net Mobile
|