节点文献

网络安全检测关键技术研究

【作者】 高翔;

【导师】 胡正国;

【作者基本信息】 西北工业大学 , 计算机软件与理论, 2004, 博士

【副题名】基于数据挖掘技术的网络异常检测方法研究

【摘要】 随着Internet在全球的普及和发展,越来越多的计算机用户可以通过网络足不出户地享受丰富的信息资源,方便快捷地收发信息。计算机网络已经和人们的学习、工作紧密的联系在一起,成为许多人生活中不可或缺的重要部分。但是,在人们享受网络带来的巨大便利时,计算机网络的安全性也日益受到关注。一方面随着网络结构的日趋复杂和应用的多元化,使得系统存在漏洞的可能性大大增加;另一方面黑客攻击手段日新月异,加之内部工作人员有意或无意的非法越权操作,对于网络的正常运行均构成了极大的威胁。原有的安全保障措施,诸如:信息加密、授权访问和防火墙等已经无法满足实际需要。入侵检测系统作为一种新兴的安全技术,主要通过监控网络与系统的状态、用户行为及资源的使用情况来发现系统内部用户的越权使用和外部入侵者的入侵攻击企图。入侵检测技术是对原有计算机网络安全机制的合理补充,它的应用极大地扩展了网络和系统安全的防御纵深。目前,入侵检测系统正在成为网络安全体系中不可或缺的重要组成部分。 本文首先阐述了当前网络所面临的安全问题以及常见的安全保障措施,并且说明了入侵检测技术的现状和发展趋势;继而针对当前入侵检测系统所面临的主要问题开展了大量的研究工作,并提出了相应的解决方法。本文的研究内容主要包括: 分析了当前主要的入侵检测技术和检测模型的优缺点,探讨了入侵检测系统当前所面临的急待解决的标准问题以及入侵检测系统性能的评估方法。 分析了当前主要的数据挖掘方法,并将关联挖掘与序列模式挖掘方法应用到基于网络的异常检测中,提出了计算挖掘正常流量与异常流量得到的规则集之间的相似度来判断网络是否发生异常的检测方法,并通过实验证实了该方法的有效性。对于包含数值属性并且带标识的网络流量数据,我们提出了先对数值属性进行聚类划分,而后再使用关联规则挖掘的检测方法。实验结果表明,该方法可以有效地进行网络误用检测。 针对现有异常检测方法实时性较差的缺陷提出了基于关联规则的在线式检

【Abstract】 With the pervading and developing of the Internet in the whole world, more and more computer users can enjoy abundant information resource, receive and send messages very quickly and conveniently through Internet without stepping out of home. Computer network has already connected closely with people’s studies and lives, so it becomes essential part of many people’s lives. But, while people are enjoying the huge convenience offered by Internet, they are concerning about computer network security increasingly. On one hand, as the structures of network are becoming more and more complex and their applications are more diverse, this greatly adds the possibility of having holes in system. On the other hand, hackers’ methods of attack are changing day-by-day; meanwhile, the inner operators illegally exceed their authority deliberately or not. They all throw a great threat on the ordinary operation of network. Original security methods, such as encryption, access control and firewall, cannot satisfy the needs nowadays. Intrusion Detection System (IDS), as a new security technology, mainly monitors the status of network and system, clients’ actions and resource condition to detect if there are any inner operators exceeding their authority or attempt of intruding and attacking the network and system. Intrusion Detection technology is rational supplement of original computer network security system. The application of it considerably strengthens network and system security. Now, it is becoming an essential part of network security system.This paper states the recent security problems we have to face and some ordinary security methods. It also illustrates the status and development tendency of Intrusion Detection technology. Then it works on a lot of research focused on the recent main problems that IDS faces, and provides the resolution. Following are the main contents of this paper: Analyzing the advantages and disadvantages of recent main Intrusion Detectiontechnology and detection models. Discussing the criteria problems to resolveimmediately and the methods to estimate IDS property.Analyzing recent main data mining methods, and applying the association and sequence pattern mining into network based anomaly detection. Providing a detection method to judge whether there happens anomaly matters. This method judges it by calculating the similarity of mining normal and anomaly traffic among the rule sets. The validity of this method is proved by experiments. As to network traffic data with quantitative attribute and labeled, we suggest that we should first process cluster partition on the quantitative attributes, then use detection method of association rule mining. Experiment results show that this method can detect network misuse effectively.As to the lack of real time reflected in existing anomaly detection methods, we provide the online detection based on association rules. And on terms of the existing network attack features, we provide a domain layer association rule mining method to combine the IP address and sub-network address bottom up, which method enhances the ability of the system detection of distribute group attack.Providing a new Intrusion Detection method based on fuzzy mining technology, and combining fuzzy logic with association rule mining and frequent episodes mining methods. Grouping the quantitative attribute in network traffic according to fuzzy set, and using genetic algorithm to construct the membership functions that state the fuzzy set. Thus avoiding the existing "sharp boundary" problem if we use classic set theory. The experiment result show combining fuzzy logic data mining method is an effective anomaly detection way.Providing an adaptive IDS framework, which is according to train data build the normal rule sets used in anomaly detection. Then adopting a dynamic association rule mining algorithm based on slide window in detection process, which updates dynamically original rule sets by data in mining window, and enables the IDS to have adaptive function.Providing an unsupervised anomaly detection method, whose traits need no special training and have very good effect on low-density attack detection. Hence, using this method to detect network traffic data in basically normal condition andadjusting detection rate, we can obtain the necessary train data used in superviseddetection method.

  • 【分类号】TP393.08
  • 【被引频次】13
  • 【下载频次】2544
  • 攻读期成果
节点文献中: 

本文链接的文献网络图示:

本文的引文网络