|
- 2015
基于广义和校准马氏距离对IP地址威胁程度的诊断
|
Abstract:
摘要 域名系统(DNS)是互联网的重要组成部分.维护DNS健康安全对整个互联网的正常运行具有十分重要的意义.通过监测并屏蔽对域名服务器具有潜在威胁的用户IP地址,达到维护DNS健康安全的目的.本文提出基于广义和校准的马氏距离2种方法,综合多个指标对IP地址的威胁程度进行诊断.这2种方法可以解决协方差阵不可逆的情形.将2种改进的马氏距离应用到实际访问DNS报文数据分析中,结果表明,它们在诊断IP的威胁程度上是非常有效的.
[1] | <p> Wikipedia. Domain name syestem[EB/OL]. America: Wikimedia Foundation. Inc.[2014-03-20]. http://en.wikipedia.org/wiki/Domain_Name_System. |
[2] | ICANN. Measuring the health of the domain name system, report of the 2<sup>nd</sup> annual symposium on DNS security, stability, & resiliency[R]. Kyoto: ICANN, 2010. |
[3] | Mockapetris P. RFC1035-domain names-implementation and specification[EB/OL]. America: Network Working Group, 1987-11, http://www.ietf.org/rfc/rfc1035.txt. |
[4] | Wikipedia. Mahalanobis distance[EB/OL]. America: Wikimedia Foundation Inc.[2014-03-22]. http://en.wikipedia.org/wiki/Mahalanobis_distance. |
[5] | Casalicchio E, Favino I N. Reference architecture, models and metrics[M/OL]. Roma: Global Cyber Security Center, (2011-07-22)[2013-10-20]. http://www.gcsec.org/sites/default/files/doc/D2%20Reference-Architecture-Models-and-Metrics.pdf. |
[6] | Antonakakis M, Perdisci R, Lee W,et al. Detecting malware domains at the upper dns hierarchy[C]//The 20<sup>th</sup> USENIX Security Symposium. USENIX Security'11. Berkeley: USENIX, 2011: 27-27. |
[7] | Mikle O, Slay K. Detecting hidden anomalies in DNS communication[C]//Casalicchio E. DNS EASY-2011. Americka: Global Cyber Security Center, 2011: 93-103. |
[8] | Casalicchio E, Fovino I N. The 3rd global stability, security and resiliency symposium final report[R]. Roma: Global Cyber Security Center, 2011. |
[9] | Mahalanobis, Chandra P. On the generalised distance in statistics[C]//Knight P. Proceedings of the National Institute of Sciences of India. India: National Institute of Sciences of India, 1936: 49-55.</p> |