%0 Journal Article %T Blood examination-based network traffic analysis framework
网络信息流的血检分析模型 %A LIU Dai-ping %A ZHANG Ming-wei %A CHEN Jia %A
刘岱坪 %A 张明威 %A 陈佳 %J 计算机应用 %D 2008 %I %X Network information stream, similar to the blood in human being, can function as the indicator of security and health status. Fluctuations of the ingredients probably implicate the changes or potential threats to the security and stability of the whole system. The mechanism of blood-examination used in medical diagnosis was employed to help analyze the security status of network. A blood-examination-based network traffic analysis framework (BETA) was presented. Firstly, the target system for traffic analysis was set up based on Hurst exponent and typical traffic packets. Secondly, the design of the knowledge base for BETA was given, and the knowledge representation was described. After that, the implementation of traffic analysis engine was expounded, and the steps of Prerequisite-Generation Algorithm (PGA) and Diagnosis Algorithm (DA) were given out in detail to realize the diagnosis of network security. At the end, the architecture of BETA and some implementation details were described. %K blood-examination %K traffic analysis %K cloud model %K Hurst exponent %K anomaly detection
血检分析 %K 流量分析 %K 云模型 %K Hurst指数 %K 异常检测 %U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=831E194C147C78FAAFCC50BC7ADD1732&aid=D3DC17F8A8169C3EE2A41D4A92B47AF5&yid=67289AFF6305E306&vid=D3E34374A0D77D7F&iid=59906B3B2830C2C5&sid=A4E99C471AEA8CA0&eid=60E4F925F9CA1CAA&journal_id=1001-9081&journal_name=计算机应用&referenced_num=0&reference_num=6