维普中文期刊产品整合服务

Efficient Feature Extraction Using Apache Spark for Network Behavior Anomaly Detection

查看全文 作  者:Xiaoming [1]Ye;Xingshu [2]Chen;Dunhu [3]Liu;Wenxian [2]Wang;Li [3]Yang;Gang [2]Liang;Guolin [4]Shao 高影响力作者 机构地区:[1]School of Cybersecurity, Chengdu University of Information Technology, Chengdu 610225, and the College of Computer Science, Sichuan University, Chengdu 610065, China;[2]College of Cybersecurity, Sichuan University, Chengdu 610065, China;[3]School of Management, Chengdu University of Information Technology, Chengdu 610103, China;[4]College of Compute Science, Sichuan University, Chengdu 610065, China高影响力机构 出  处:《Tsinghua Science and Technology》索引2018年第23卷第5期,共13页高影响力期刊 基  金:supported by the National Natural Science Foundation of China (No. 61272447);Sichuan Province Science and Technology Planning (Nos. 2016GZ0042, 16ZHSF0483, and 2017GZ0168);Key Research Project of Sichuan Provincial Department of Education (Nos. 17ZA0238 and 17ZA0200);Scientific Research Staring Foundation for Young Teachers of Sichuan University (No. 2015SCU11079) 摘  要:Extracting and analyzing network traffic feature is fundamental in the design and implementation of network behavior anomaly detection methods. The traditional network traffic feature method focuses on the statistical features of traffic volume. However, this approach is not sufficient to reflect the communication pattern features. A different approach is required to detect anomalous behaviors that do not exhibit traffic volume changes,such as low-intensity anomalous behaviors caused by Denial of Service/Distributed Denial of Service(Do S/DDo S)attacks, Internet worms and scanning, and Bot Nets. We propose an efficient traffic feature extraction architecture based on our proposed approach, which combines the benefit of traffic volume features and network communication pattern features. This method can detect low-intensity anomalous network behaviors and conventional traffic volume anomalies. We implemented our approach on Spark Streaming and validated our feature set using labelled real-world dataset collected from the Sichuan University campus network. Our results demonstrate that the traffic feature extraction approach is efficient in detecting both traffic variations and communication structure changes.Based on our evaluation of the MIT-DRAPA dataset, the same detection approach utilizes traffic volume features with detection precision of 82.3% and communication pattern features with detection precision of 89.9%. Our proposed feature set improves precision by 94%. 关 键 词:特征抽取 网络行为 APACHE 火花 网络通讯模式 交通特征 异常行为 拒绝服务
相关文献

参考文献(35)

引证文献(2)

耦合文献(6)

网站首页 | 关于我们 | 联系我们 | 产品服务 | 客服中心 | 广告服务 | 版权声明 | 网站联盟 | 友情链接 | 售卡网点

版权所有© 渝B2-20050021-1 渝公网安备 50019002500403号 违法和不良信息举报中心

互联网出版许可证 新出网证(渝)字10号 全国400电话 - 免长途话费