Autor: |
Yun-long MA, Cai-ping JIANG, Qian-li ZHANG, Ji-long WANG |
Jazyk: |
čínština |
Rok vydání: |
2014 |
Předmět: |
|
Zdroj: |
Tongxin xuebao, Vol 35, Pp 5-9 (2014) |
Druh dokumentu: |
article |
ISSN: |
1000-436X |
DOI: |
10.3969/j.issn.1000-436x.2014.z1.002 |
Popis: |
An algorithm based on IPFIX network flow data is proposed.By using proposed algorithm,suspicious and abnormal DNS will be detected accurately,and DNS traffic amplification attack will be distinguished rapidly.This algorithm has been applied in the Tsinghua University campus network.In our practice,DNS abnormal behaviors have been detected and alarm information has been sent to administrators.Thus,abnormal attack behaviors are restrained in time,and the monitoring and warning for abnormal traffic are all realized. |
Databáze: |
Directory of Open Access Journals |
Externí odkaz: |
|