摘要
计算机网络缓存侧信道能够间接体现计算机内部状态以及数据传输情况,其受攻击时,用户端信息数据存在泄露风险,因此提出一种基于马尔科夫的计算机网络缓存侧信道攻击检测方法。构建隐马尔科夫模型,对计算机网络缓存侧信道状态改变的概率进行计算。通过Baum‐Welch算法估计隐马尔科夫模型最优参数,并计算缓存侧信道状态观测序列输出概率。比较缓存侧信道观测序列输出概率与设定的阈值,判断该序列为计算机网络缓存侧信道攻击信号的可能性,并引入平均信息熵判断计算机缓存侧信道状态是否存在异常,完成计算机网络缓存侧信道攻击检测。通过实验验证得出,该方法用于计算机网络缓存侧信道攻击检测的准确率高,误报率低,在遭受DDoS攻击(Distributed denial of service)时的检测时间较短,对计算机网络缓存侧信道攻击的防御与保护产生了积极影响。
As the computer network cache side channel indirectly reflects the internal state and data transmission situation of the computer,there is a risk of leakage of user‐side information data when it is attacked.Therefore,a Markovbased detection method for computer network cache side channel attack was proposed.A hidden Markov model was constructed to calculate the probability of channel state changes on the cache side of the computer network.The optimal parameters of the hidden Markov model were estimated by Baum Welch algorithm,and the output probability of the channel state observation sequence on the cache side was calculated.Comparing the output probability of the cache side channel observation sequence with the set threshold,the possibility of the sequence being a computer network cache side channel attack signal was determined.Meanwhile,the average information entropy was employed to determine any abnormality in the computer cache side channel state,to complete the detection of computer network cache side channel attacks.Through experimental verification,it was found that the present method has high accuracy and low false alarm rate when employed in computer network cache side channel attack detection,and a short detection time when subjected to DDoS attacks(Distributed Denial of Service).The method exerts a positive impact on the defense and protection of cache side channel attacks in computer networks.
作者
黄丽芳
HUANG Lifang(School of Information Management,Minnan University of Science and Technology,Shishi Fujian 362700,China)
出处
《海南热带海洋学院学报》
2024年第5期104-110,118,共8页
Journal of Hainan Tropical Ocean University
基金
闽南理工学院科技创新团队项目(23XTD114)。
作者简介
黄丽芳,女,福建仙游人,讲师,硕士,研究方向为云计算、数据挖掘以及计算机网络安全。