Anomaly traffic detection of database network based on flow statistical features

Xinliang WANG,Fang LIU,Luying CHEN,Zhenming LEI,

PDF(127 KB)
PDF(127 KB)
Front. Electr. Electron. Eng. ›› 2010, Vol. 5 ›› Issue (1) : 85-90. DOI: 10.1007/s11460-009-0071-5
Research articles
Research articles

Anomaly traffic detection of database network based on flow statistical features

  • Xinliang WANG,Fang LIU,Luying CHEN,Zhenming LEI,
Author information +
History +

Abstract

The traditional intrusion detection system has the problem of high false positive rate and false negative rate. This paper deeply analyzes the differences of statistical features between single-flow and multi-flow on the database network, and presents a group of features that are easy to acquire and can be used to detect the anomaly in database network efficiently. By applying this group of features in Fisher algorithm for anomaly detection, the false positive rate and false negative rate are dramatically reduced. Simultaneously, the model made by using the group of features has the advantages of low algorithm complexity, good detection result and strong generalization ability. Experimental results show that there is higher accuracy when using the features of single-flow and multi-flow to construct the anomaly detection model than only using single-flow features.

Cite this article

Download citation ▾
Xinliang WANG, Fang LIU, Luying CHEN, Zhenming LEI,. Anomaly traffic detection of database network based on flow statistical features. Front. Electr. Electron. Eng., 2010, 5(1): 85‒90 https://doi.org/10.1007/s11460-009-0071-5
PDF(127 KB)

Accesses

Citations

Detail

Sections
Recommended

/