Security Evaluation Method Based on Real Time Traffic of Hosts

Tingting Yao,Qinghua Zheng,Xiaohong Guan,Xiuzhen Chen
DOI: https://doi.org/10.3321/j.issn:0253-987X.2006.04.011
2006-01-01
Abstract:After analyzing malicious attacks against network that affect the service availability and would lead to the abnormal change of the network traffic, a method to evaluate the security situation of real-time traffic of hosts is presented. A group of statistic that can reflect the network traffic features in a fixed time window are selected as the evaluation metrics. Based on the large samples, the information entropy gain method is applied to determine the importance of evaluation results for different metrics. Then, using hierarchical weighted method, the evaluation results are regarded as the normalized abnormality value to evaluate the real time traffic of host networks. Experiments and testing show that this method can reasonably evaluate the host network abnormal flows caused by the DDoS, DoS worm and other attacks, and has good evaluation results for new attacks that cause abnormal change of network traffic.
What problem does this paper attempt to address?