针对现有的局域网评估模型不能提供局域网系统中数据传输安全的有效信息的缺陷,文中提出了一种通过分析局域网网关流量的自相似性变化,来对局域网系统的数据传输安全进行合理评估的方法.该方法通过选择合适的时间尺度,利用whittle估计器法计算多种测度的自相似系数,判断测度值是否偏离正常值范围来综合分析局域网流量的异常状况.在此基础上,提出了改进的局域网系统安全评估模型.实验证明,此方法能够反映网络攻击等多种原因导致的流量异常变化,提供给管理员直观的数据传输安全态势图.
Aiming at the deficiency that unable to provide effective security information about network data transmission information in current LAN security evaluation system,a security evaluation method,which analyzes the self-similarity of traffic on router,is proposed.After choose the suitable time-scale,whittle estimator is applied for calculate the self-similar parameters of four evaluate metrics.We study the abnormal situation of traffic on LAN by calculate the distances between the self-similar parameters and normal values.A reformative model for evaluates the LAN's security is given on the base of before-mentioned method.Experiment results show that our method is able to evaluate the abnormal change on traffic caused by several reasons.It provide system administrator with intuitive security curve that expresses the risk of network system data transmission.