节点文献

网络入侵检测系统及其自适应性的研究与实现

Study and Realization of Network Intrusion Detection System and Its Adaptive Ability

【作者】 刘棣华

【导师】 陈家训;

【作者基本信息】 东华大学 , 控制理论与控制工程, 2009, 博士

【摘要】 随着计算机网络的迅速发展,网络入侵事件频繁发生,人们逐渐认识到只从防御的角度构造安全系统是不够的,仅仅使用防火墙、数据加密等传统安全防护措施已经不能满足对网络安全的需求。入侵检测是新一代安全保障技术,是对传统安全防护措施的必要、有效的补充。入侵检测作为一种积极主动的安全防护技术,它不仅能检测未经授权的对象入侵系统,而且也能监视授权对象对系统资源的非法使用。在收集、分析、整理和总结现有入侵检测技术资料的基础上,论文设计实现了包含控制台级、管理器级和检测代理级的三级层次结构的分布式网络入侵检测系统。三级分布式结构使得网络入侵检测系统能够很好地适应大型网络的需要。论文提出了一种新的检测规则表达方法,该方法与现有的检测规则表达方法相比,能更精确地描述检测特征。在网络入侵检测系统内部,检测规则以符号表的形式存储,检测规则的匹配通过符号表的搜索来完成,提高了检测速度。针对在实际网络中不宜进行有干扰性和破坏性的网络攻击实验的情况,论文提出了一种新的离线状态下测试评估网络入侵检测系统的方法,开发了模拟实际网络背景流量的仿真软件,进而对所设计实现的网络入侵检测系统从检测能力、易用性、检测性能和安全性多方面进行了全面测试,测试结果得到了中国国家信息安全评测认证中心东北测试中心的肯定。将理论方法的研究与探讨结果和应用系统的开发与实现紧密相结合是本论文的重要特点。已实现的网络入侵检测系统已在吉林省某部队应用,效果良好。在此基础上,论文进一步将关联规则挖掘、基于决策树的分类以及序列模式挖掘等数据挖掘技术综合应用于入侵检测,提出了一种新的综合应用数据挖掘技术的入侵检测的自适应方法。实验证明,所采用的综合数据挖掘方法能够及时生成新规则,使网络入侵检测系统具有应对不断变化的网络攻击的自适应能力。

【Abstract】 With the rapid development of networks,more and more emerging events of network intrusion make people realize that it is insufficient to build security system only with some passive techniques.The traditional security model such as firewall and data encrypt can not keep up with the rapid development of modern network technology.Intrusion detection(ID) is a new generation security protecting technology and it is a necessary and effective supplement to the traditional security protecting technology.As a kind of active security technique,ID can not only detect the unauthorized objects intruding the system,but also monitor the authorized objects using the system resource unlawfully.In this paper,based on the collection,analysis,sorting out and summarization of references now available about intrusion detection technology,a three layered distributed network intrusion detection system(NIDS) is designed and realized.The three layered distributed structure makes the NIDS suitable for the requirement of large scale networks.In the paper,a new expression method of detection rules is advanced.Compared with the other expression methods now available,the new expression method can describe the detection characters more accurately.In the detection system,the detection rules are stored as symbol tables,and the match of detection rules is realized by searching the symbol tables,which can shorten the detection time.Because it is not suitable to do network attack tests,which are interferential and damageable on a real network environment,a new kind of method for testing and evaluating NIDS in off-line status is proposed in the paper.The software that simulates data flowing of network backgrounds is developed.The tests have been made,which are about detection ability,ease of use,detection performance, security and so on of the designed and realized NIDS.The results of the tests have been confirmed by Northeast Test Centre of Chinese National Information Security Certification Centre.An important character of this paper is combining results of research and discussing about theory methods with developing and realizing of application system closely.The realized NIDS has already been used in the army network of Jilin province and has got good results.On the basis of this,a new kind of adaptive method for intrusion detection is proposed,which comprehensively utilize the data mining techniques of association rule mining,decision tree based classifying and sequential pattern mining.The experiments show that the comprehensive utilization method of data mining techniques can create new rules in time,so that the NIDS have the ability of adaptive to cope with the continuing change of network attacks.

  • 【网络出版投稿人】 东华大学
  • 【网络出版年期】2009年 10期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络