Computer Engineering and Applications ›› 2009, Vol. 45 ›› Issue (17): 95-98.DOI: 10.3778/j.issn.1002-8331.2009.17.029

• 网络、通信、安全 • Previous Articles     Next Articles

Design and implementation of anomaly detection system for earth-station

CHEN Ning-jun1,LUO Jun2,XIAO Jia3   

  1. 1.Dept. of Battle Experiment,the Army Command College,Nanjing 210045,China
    2.Research Center of Information War,the Navy Command College,Nanjing 211800,China
    3.Cannoneer-regiment of Jiangsu Military Area,Lianyungang,Jiangsu 222000,China
  • Received:2008-04-08 Revised:2008-07-11 Online:2009-06-11 Published:2009-06-11
  • Contact: CHEN Ning-jun

一种地球站异常检测系统的设计与实现

陈宁军1,罗 隽2,肖 佳3   

  1. 1.南京陆军指挥学院 作战实验中心,南京 210045
    2.海军指挥学院 浦口分院信息战研究教育中心,南京 211800
    3.江苏省军区连云港警备区炮兵团,江苏 连云港 222000
  • 通讯作者: 陈宁军

Abstract: As more and more widely used of satellite communications network,more and more attention is paid on its security.Aiming at possible problems of satellite communications network that may seriously threaten its security,such as lost or falsification of portable earth-station,the idea of anomaly detection of station behavior is brought forword,and by means of combining cluster and pattern recognition technology,an anomaly detection system of satellite communication network is designed and realized.An anomaly detection algorithm is presented based on improved KFCM cluster algorithm which can achieve partial best partition.Experimental results show that the improved algorithm reaches a better clustering result,and the system gets good ability of anomaly detecting.

Key words: anomaly detection, station behavior, clustering analysis, Kenerl Fuzzy C Means(KFCM), best partition

摘要: 随着卫星通信网的推广,其安全性越来越重要。针对卫星通信网中可能出现的严重威胁其自身安全的地球站被盗用或伪造等问题,提出了地球站行为异常检测的概念,采用聚类分析和模式匹配相结合的检测方法,设计并实现了一个卫星通信网地球站异常检测系统。提出了一种改进的KFCM聚类异常检测算法,该算法可获得局部最优划分。实验结果表明,改进后的算法具有更好的聚类效果,系统达到了较好的检测性能。

关键词: 异常检测, 地球站行为, 聚类分析, 核函数的模糊C均值算法, 最优划分