一种时序驱动的Web攻击行为同源分析方法OA
A Time Series Driven Homology Analysis Method for Web Attack Behaviors
针对现有网络攻击同源分析方法在攻击行为相似性度量上存在不足、且在多密度样本与高噪声场景下同源分析准确度低的问题,提出一种时序驱动的Web攻击行为同源分析方法.首先,提取3类20种Web攻击警报特征,构建攻击序列;其次,提出一种攻击序列相似度算法,计算序列间相似度并构建距离矩阵;最后,基于距离矩阵设计聚类算法,对攻击序列进行聚类,进而实现攻击同源分析.相较于仅依靠统计特征分析的传统方法,该方法将攻击行为的时序关联性纳入同源分析范畴,有效提升了Web攻击同源分析的准确度.实验结果显示,在噪声环境中,该方法的关键指标调整兰德指数(ARI)达94.9%,验证了同源分析效果优于其他方法,同时在较宽参数范围内能够保持性能稳定.
To address the problems that existing network attack homology analysis methods suffer from insufficient measurement of attack behavior similarity and low accuracy in multi-density samples and high-noise scenarios,a time series driven homology analysis method for Web attack behaviors is pro-posed.Firstly,3 categories of 20 Web attack alert features are extracted to construct attack series.Then,a similarity algorithm for attack series is proposed to calculate the similarity between sequences and construct a distance matrix.Finally,a clustering algorithm is designed based on the distance ma-trix to cluster attack sequences,thereby realizing attack homology analysis.Different from traditional methods relying only on statistical feature analysis,the proposed method incorporates the temporal cor-relation of attack behaviors into homology analysis and effectively improves the accuracy of Web attack homology analysis.Experimental results show that the key indicator ARI of the method reaches 94.9%in noisy environments,verifying that its homology analysis performance outperforms other methods.Meanwhile,the method can maintain stable performance within a wide range of parameters.
高耀军;张震;王文博;王亚文
信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001
信息技术与安全科学
高级持续性威胁Web攻击同源分析动态时间规整聚类
advanced persistent threatWeb attackhomology analysisdynamic time warpingclustering
《信息工程大学学报》 2026 (3)
316-322,7
国家科技重大专项(2025ZD1501300)
评论