信息网络安全 ›› 2018, Vol. 18 ›› Issue (3): 78-85.doi: 10.3969/j.issn.1671-1122.2018.03.010

• • 上一篇    下一篇

一种结合网络行为分析的可信连接架构

张建标, 徐万山(), 刘国杰, 杨帆   

  1. 北京工业大学信息学部,北京100124
  • 收稿日期:2017-11-10 出版日期:2018-03-15 发布日期:2020-05-11
  • 作者简介:

    作者简介:张建标(1969—),男,江苏,教授,博士,主要研究方向为信息安全与可信计算;徐万山(1988—),男,山东,硕士研究生,主要研究方向为信息安全;刘国杰(1983—),男,山东,博士研究生,主要研究方向为可信计算;杨帆(1993—),男,北京,硕士研究生,主要研究方向为可信计算、大数据。

  • 基金资助:
    国家自然科学基金[61671030];国家高技术研究发展计划(863计划)[2015AA016002]

A Trusted Connection Architecture Based on Network Behavior Analysis

Jianbiao ZHANG, Wanshan XU(), Guojie LIU, Fan YANG   

  1. Faculty of Information Technology, Beijing University of Technology, Beijing 100124, China
  • Received:2017-11-10 Online:2018-03-15 Published:2020-05-11

摘要:

可信连接架构(TCA)是解决网络安全接入的重要手段。TCA通过可信第三方实现双向用户身份鉴别和平台鉴别,极大地保证了终端和接入网络的安全性。然而,TCA并没有考虑网络行为的安全性,对此,文章提出一种扩展的TCA架构,在TCA的基础上扩展了网络行为层,提取网络行为基于时间和主机的网络流量特征,利用贝叶斯算法实现网络行为的分析、度量,识别网络异常行为。实验表明,该架构能准确识别网络中的异常行为,有效地保障网络安全。

关键词: TCA, 行为分析, 贝叶斯算法, 网络安全

Abstract:

Trusted connection architecture (TCA) is an important means to solve the network security access. TCA through a trusted third party to achieve two-way user authentication and platform identification, greatly guarantee the terminal and access network security. TCA implements two-way user authentication and platform authentication through trusted third party, which greatly guarantees the security of the terminal and the network access. However, TCA does not consider the security of network behavior. In this regard, this paper proposes an extended TCA architecture, which extends the network behavior layer on the basis of TCA. It extracts network behavior based on time and host network traffic characteristics. Bayesian algorithm is used to achieve the network behavior analysis, measurement and identify the network abnormal behavior. Experiments show that the architecture can effectively identify the abnormal behavior in the network and protect the network security.

Key words: TCA, behavior analysis, Bayesian algorithm, network security

中图分类号: