An Adaptive lnternet Backbone Traffic Anomalies Detection Algorithm Based on Frequent Pattern Mining
Rong Gu · 2006
DDOS,worm and mass mailing have a significant growth recent years,which has endangered Internet secur- ity.Most attack like worm has the nature of aggressive,greedy and behavior pattern of self-similar.This paper pro- posed an attack behavior analysis based model,TIR model and devised a fast algorithm based on frequent pattern min- ing.It can effectively detect known or unknown threats with a low cost and has the ability to report the suspicious ad- dress.This paper also puts forward an effective algorithm to improve the real-time detection performance,namely 2- page hash table algorithm.As a result we developed a distributed system namely M-Detector based our theories.