SUN Zhi-xin1, TANG Yi-wei1, GONG Jing1. Novel wobble-defended M-MULTOPS structure and its application in detecting network abnormal traffic[J]. 2007, (8): 92-98.
SUN Zhi-xin1, TANG Yi-wei1, GONG Jing1. Novel wobble-defended M-MULTOPS structure and its application in detecting network abnormal traffic[J]. 2007, (8): 92-98.DOI:
防抖动的M-MULTOPS结构在网络异常流量检测中的应用
摘要
提出了一种新的异常流量检测方法:防抖动的M-MULTOPS(modified-multi-level tree for online packet statistics)结构。针对核心路由器中网络流量的变化
A new detection method: wobble defended M-MULTOPS(modified-multi-level tree for online packet statistics) structure was presented.Aiming at the change of network traffic in core routers
ABF(adapted bloom filter) algorithm to assemble destination addresses to the IP packets was employed.And it put forward M-MULPOTS struc-ture to analyze results of the ABF algorithm
monitoring changes of network traffic and detecting network flow ab-normity in real time.For making use of the Wobble-defended M-MULTOPS structure
the method can work steadily and exactly
even when the traffic of network is wobbling terribly by the pulse attack.And because the M-MULTOPS inherits the MULTOPS ’s flexible attribution
it declined the spending of system resources at maximum.A detection system em-ploying this method has been run successfully in routers as an individual module.