详细信息

Research of MDCOP Mining Based on Time Aggregated Graph for Large Spatio-temproal Data Sets  ( SCI-EXPANDED收录)  

文献类型:期刊文献

英文题名:Research of MDCOP Mining Based on Time Aggregated Graph for Large Spatio-temproal Data Sets

作者:Wang, Zhanquan[1,2];Han, Taoli[1];Yu, Huiqun[1,2]

机构:[1]East China Univ Sci & Technol, Dept Comp Sci & Engn, Shanghai 200237, Peoples R China;[2]Shanghai Engn Res Ctr Smart Energy, Shanghai 200237, Peoples R China

年份:2019

卷号:16

期号:3

起止页码:891

外文期刊名:COMPUTER SCIENCE AND INFORMATION SYSTEMS

收录:;WOS:【SCI-EXPANDED(收录号:WOS:000494947400011)】;

语种:英文

外文关键词:Network spatiotemporal co-occurrence pattern intrusion detection; mixed-drove spatiotemporal co-occurrence pattern; large spatiotemporal data set; Time Aggregated Graph (TAG); file index

摘要:Discovering mixed-drove spatiotemporal co-occurrence patterns (MDCOPs) is important for network security such as distributed denial of service (DDoS) attack. There are usually many features when we are suffering from a DDoS attacks such as the server CPU is heavily occupied for a long time, bandwidth is hoovered and so on. In distributed cooperative intrusion, the feature information from multiple intrusion detection sources should be analyzed simultaneously to find the spatial correlation among the feature information.In addition to spatial correlation, intrusion also has temporal correlation. Some invasions are gradually penetrating, and attacks are the result of cumulative effects over a period of time. So it is necessary to discover mixed-drove spatiotemporal co-occurrence patterns (MDCOPs) in network security. However, it is difficult to mine MDCOPs from large attack event data sets because mining MDCOPs is computationally very expensive. In information security, the set of candidate co-occurrence attack event data sets is exponential in the number of object-types and the spatiotemporal data sets are too large to be managed in memory. To reduce the number of candidate co-occurrence instances, we present a computationally efficient MDCOP Graph Miner algorithm by using Time Aggregated Graph. which can deal with large attack event data sets by means of file index. The correctness, completeness and efficiency of the proposed methods are analyzed.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心