欢迎访问中国科学院大学学报,今天是
数学与物理学

基于广义和校准马氏距离对IP地址威胁程度的诊断

  • 钞婷 ,
  • 李启寨 ,
  • 刘卓军 ,
  • 孙才 ,
  • 孙云刚
展开
  • 1. 中国科学院数学与系统科学研究院, 北京 100049;
    2. 中国互联网络信息中心, 北京 100190

收稿日期: 2013-12-31

  修回日期: 2014-03-31

  网络出版日期: 2015-01-15

基金资助

国家自然科学基金(11371353)和中国互联网络信息中心研究课题(DNSLAB-2012-N-U)资助

Diagnosis of threat degree of IP addresses based on the generalized and regularized Mahalanobis distances

  • CHAO Ting ,
  • LI Qizhai ,
  • LIU Zhuojun ,
  • SUN Cai ,
  • SUN Yungang
Expand
  • 1. Academy of Mathematics and Systems Science, Chinese Academy of Sciences, Beijing 100049, China;
    2. China Internet Network Information Center, Beijing 100190, China

Received date: 2013-12-31

  Revised date: 2014-03-31

  Online published: 2015-01-15

摘要

域名系统(DNS)是互联网的重要组成部分.维护DNS健康安全对整个互联网的正常运行具有十分重要的意义.通过监测并屏蔽对域名服务器具有潜在威胁的用户IP地址,达到维护DNS健康安全的目的.本文提出基于广义和校准的马氏距离2种方法,综合多个指标对IP地址的威胁程度进行诊断.这2种方法可以解决协方差阵不可逆的情形.将2种改进的马氏距离应用到实际访问DNS报文数据分析中,结果表明,它们在诊断IP的威胁程度上是非常有效的.

本文引用格式

钞婷 , 李启寨 , 刘卓军 , 孙才 , 孙云刚 . 基于广义和校准马氏距离对IP地址威胁程度的诊断[J]. 中国科学院大学学报, 2015 , 32(1) : 18 -24 . DOI: 10.7523/j.issn.2095-6134.2015.01.004

Abstract

The domain name system (DNS) plays an important role in the internet, and maintaining its health and security is significant to the normal operation of the entire internet. To this end, we detect and shield the IP addresses that have potential threats to the name servers. We propose the generalized and regularized Mahalanobis distances to diagnose the threat degree of IP addresses. Both the methods efficiently solve the issue where the covariance matrix is singular. Real data analysis shows that the two proposed distances are very efficient in the diagnosis of threat degree of IP addresses.

参考文献

[1] Wikipedia. Domain name syestem[EB/OL]. America: Wikimedia Foundation. Inc.[2014-03-20]. http://en.wikipedia.org/wiki/Domain_Name_System.

[2] Casalicchio E, Favino I N. Reference architecture, models and metrics[M/OL]. Roma: Global Cyber Security Center, (2011-07-22)[2013-10-20]. http://www.gcsec.org/sites/default/files/doc/D2%20Reference-Architecture-Models-and-Metrics.pdf.

[3] Antonakakis M, Perdisci R, Lee W,et al. Detecting malware domains at the upper dns hierarchy[C]//The 20th USENIX Security Symposium. USENIX Security'11. Berkeley: USENIX, 2011: 27-27.

[4] Mikle O, Slay K. Detecting hidden anomalies in DNS communication[C]//Casalicchio E. DNS EASY-2011. Americka: Global Cyber Security Center, 2011: 93-103.

[5] Casalicchio E, Fovino I N. The 3rd global stability, security and resiliency symposium final report[R]. Roma: Global Cyber Security Center, 2011.

[6] ICANN. Measuring the health of the domain name system, report of the 2nd annual symposium on DNS security, stability, & resiliency[R]. Kyoto: ICANN, 2010.

[7] Mockapetris P. RFC1035-domain names-implementation and specification[EB/OL]. America: Network Working Group, 1987-11, http://www.ietf.org/rfc/rfc1035.txt.

[8] Wikipedia. Mahalanobis distance[EB/OL]. America: Wikimedia Foundation Inc.[2014-03-22]. http://en.wikipedia.org/wiki/Mahalanobis_distance.

[9] Mahalanobis, Chandra P. On the generalised distance in statistics[C]//Knight P. Proceedings of the National Institute of Sciences of India. India: National Institute of Sciences of India, 1936: 49-55.

文章导航

/