A Router Abnormal Traffic Detection Strategy Based on Active Defense

Xin Li,Peng Yi,Yiming Jiang,Jing Yu
DOI: https://doi.org/10.1088/1742-6596/1738/1/012103
2021-01-01
Journal of Physics Conference Series
Abstract:Abstract With the rapid development of network attacks, traditional security protection technology is difficult to deal with unknown threats and persistent attacks. Active defense improves the ability to defend against network attacks by building a dynamic, heterogeneous and redundant endogenous security system. Aiming at the problem of single abnormal arbitrament information of routers in mimic defense, a router abnormal traffic detection strategy based on active defense is proposed. By clustering the traffic information of multiple heterogeneous redundant routing function entities and comparing the distance measurement between them, the routing function entities in abnormal state are determined. The experimental results show that the proposed strategy effectively detects the security threats of routing functional entities and expand the method of mimic router arbitrament.
What problem does this paper attempt to address?