节点文献

入侵检测系统中的行为模式挖掘

Behavior profile mining in intrusion detection system

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王丽苹安娜吴晓南房鼎益

【Author】 WANG Li-ping, AN Na, WU Xiao-nan, FANG Ding-yi (Computer Science Department, Northwest University, Xian 710069,China)

【机构】 西北大学计算机科学系西北大学计算机科学系 陕西西安710069陕西西安710069陕西西安710069

【摘要】 提出了一种利用模式挖掘技术进行网络入侵防范的方法及其入侵检测系统模型,设计并实现了一个基于关联规则的增量式模式挖掘算法。通过对网络数据包的分析,挖掘出网络系统中频繁发生的行为模式,并运用模式相似度比较对系统的行为进行检测,进而自动建立异常和误用行为的模式库。实验结果证明,本文提出的方法与现有的入侵检测方法相比,具有更好的环境适应性和数据协同分析能力,相应的入侵检测系统具有更高的智能性和扩展性。

【Abstract】 An efficient profile mining model based on distributed system is proposed, which is used in the intrusion detecting systems. By analysis of network traffic (packets), frequent user behavior profiles are mined, and then by comparing the profile similarity, system behavior can be detected in real-time. Meanwhile, anomaly and misuse behavior profile base can be build automatically as well. Compared with most existing intrusion detection methods, our method is more adaptive, cooperative and the corresponding system is more extensible, intelligent.

【基金】 航空科学基金资助项目(GIYB0302-11);陕西省教育厅重点科研基金资助项目(01ZC26)
  • 【文献出处】 通信学报 ,Journal of China Institute of Communications , 编辑部邮箱 ,2004年07期
  • 【分类号】TP393.08
  • 【被引频次】34
  • 【下载频次】362
节点文献中: 

本文链接的文献网络图示:

本文的引文网络