北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2018, Vol. 41 ›› Issue (4): 56-62.doi: 10.13190/j.jbupt.2017-257

• 论文 • 上一篇    下一篇

基于熵和线性关系的两级流量异常检测方法

邱雪松1, 张珣1, 宋彦斌2, 赵兵3, 徐思雅1   

  1. 1. 北京邮电大学 网络与交换技术国家重点实验室, 北京 100876;
    2. 北京智芯微电子科技有限公司, 北京 102200;
    3. 中国电力科学研究院, 北京 100192
  • 收稿日期:2017-12-25 出版日期:2018-08-28 发布日期:2018-10-09
  • 作者简介:邱雪松(1973-),男,教授,博士生导师;张珣(1993-),女,硕士生,E-mail:zhangxunbupt@163.com.
  • 基金资助:
    国家自然科学基金项目(61702048)

Two-Stage Traffic Anomaly Detection Method Based on Entropy and Linear Relation

QUI Xue-song1, ZHANG Xun1, SONG Yan-bin2, ZHAO Bing3, XU Si-ya1   

  1. 1. State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China;
    2. Beijing Smartchip Microelectronics Technology Company Limited, Beijing 102200, China;
    3. China Electric Power Research Institute, Beijing 100192, China
  • Received:2017-12-25 Online:2018-08-28 Published:2018-10-09

摘要: 提出了一种基于熵和线性关系的两级流量异常检测方法,综合考虑了流量异常检测方法的准确性和实时性要求.该方法在时间域上设定两级动态阈值,采用基于熵的方法对异常时间点进行检测,对熵值变化程度明显的时间点可使用一级阈值检测出来,而对熵值变化程度处于一级阈值和二级阈值之间的时间点采用基于线性关系的方法再次进行检测,并通过定义的报警触发函数识别异常类型.仿真实验结果证明,该方法在准确性和实时性方面优于现有的方法.

关键词: 流量异常检测, 熵, 线性关系, 两级阈值

Abstract: To improve the accuracy and real-time traffic anomaly detection methods, a two-stage traffic anomaly detection method based on entropy and linear relation was presented. A two-level dynamic threshold was set and used based on entropy and linear relation to detect abnormal traffic in time domain. The type of traffic anomaly can be indentified through the alarm trigger function. Simulations verify that this method is superior to the existing methods in the accuracy and real-time respects.

Key words: traffic anomaly detection, entropy, linear relation, two-level threshold

中图分类号: