计算机与现代化 ›› 2025, Vol. 0 ›› Issue (06): 56-60.doi: 10.3969/j.issn.1006-2475.2025.06.009

• 算法设计与分析 • 上一篇    下一篇

基于流量数量的网络态势感知方法

  

  1. (1.中国电子科技集团公司第十五研究所,北京 100083; 2.中国人民解放军海军研究院,北京 102442)
  • 出版日期:2025-06-30 发布日期:2025-07-01
  • 作者简介: 作者简介:邝野(1992—),男,重庆人,工程师,博士,研究方向:网络空间安全,E-mail: 463371090@qq.com; 周末(1994—),女,天津人,助理研究员,硕士,研究方向:计算机网络,E-mail: zhoumo941231@163.com; 刘策越(1986—),男,吉林省吉林市人,高级工程师,博士,研究方向:网络空间安全,E-mail: liuceyue@163.com。

Cyberspace Situational Awareness Method Based on Traffic Volume

  1. (1.The 15th Research Institute of China Electronics Technology Group Corporation, Beijing 100083, China;
    2. Naval Research Institute, Beijing 102442, China)
  • Online:2025-06-30 Published:2025-07-01

摘要: 摘要:网络状态的变化会严重影响基础设施的正常运行,并造成巨大的经济损失。现有的研究通过观察网络流量的变化来感知网络状态的变化。然而,由于缺乏量化指标,这些网络态势感知方法存在误报率较高、准确性较低等问题。为了解决这些问题,本文提出一种新的基于流量数量的网络态势感知方法来解决这些挑战。具体来说,基于公开数据集获取到的检测区域流量信息,首先,提出一种基于威尔逊分数的流量临界值确定算法,计算得到每条链路对应的流量临界值。然后,提出一种网络状态感知方案,通过监测检测区域内任意一条链路的流量数量是否低于本文给出的流量临界值并持续11 min来感知网络状态的变化。最后,本文使用来自公共测量基础设施(RIPE Atlas)的数据进行实验,以评估方法的性能。实验结果表明,本文方法可以有效地感知网络状态的变化。


关键词: 关键词:网络态势感知, 网络流量, 威尔逊分数, 临界值

Abstract: Abstract: Network anomalies can seriously influence the normal operation of infrastructure and cause huge financial losses. Existing studies perceived the changes of network state by observing the changes of network traffic. However, due to the lack of quantitative indicators, these cyberspace situational awareness methods have the problems of high false positive rate and low accuracy. This paper proposes a new cyberspace situational awareness method to address these challenges. Specifically, we use the public data set to obtain the traffic information of the links in the detection area. Firstly, a traffic critical value determination algorithm based on Wilson score is proposed to calculate the corresponding traffic threshold of each link. Secondly, a network state awareness scheme is proposed, which perceives the change of network state by monitoring whether the traffic volume of any link in the detection area is lower than the critical value and lasts for 11 minutes. Finally, this paper perform experiments with data from public measurement infrastructures (RIPE Atlas) to evaluate the performance of our approach, and the results show that our approach can effectively perceive the changes of network state.

Key words: Key words: cyberspace situational awareness, network traffic, Wilson score, critical value

中图分类号: