节点文献

时间序列模型在入侵检测中的应用研究

Research of applying time-based sequence model to intrusion detection

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 赵铁山李增智高波

【Author】 ZHAO Tie-shan 1,2 , LI Zeng-zhi 1 , GAO Bo 2 (1. Institute of Computer Architecture and Network, Xi’an Jiaotong University, Xi’an 710049, China; 2. Department of Technique, Xichang Satellite Launch Center, Xichang 615000, China)

【机构】 西安交通大学计算机系统结构与网络研究所中国西昌卫星发射中心技术部 陕西西安710049中国西昌卫星发射中心技术部四川西昌615000陕西西安710049四川西昌615000

【摘要】 入侵检测是计算机系统安全技术的重要组成部分,是计算机领域当前研究热点之一。提出了一种用于入侵检测的时间序列模型。对于计算机系统运行的某一时段,用前K次审计时事件发生次数的均值作为第K+1次的期望值,然后求期望值和第K+1次的实际次数的相对误差。当相对误差超过某一阈值时,则认为在第K+1次发生了入侵。通过仿真揭示了阈值的选择规律。仿真结果证明,在突然发生较多的入侵事件时,模型工作良好。

【Abstract】 Intrusion detection is an important part of computer security. It is a research hotspot. A time-based sequence model applying to intrusion detection is brought forward. In some period of time of a running computer system, mean value of an event’s frequency in k audits is taken as expected value at k+1th audit. Relative error of the expected value and real value at k+1th audit is computed. If the relative error is bigger than some set threshold, an intrusion occurs at K+1th audit. Simulation results open out how to select threshold. If a large amount of intrusion events appear in a short time, the model works effectively.

【基金】 国家863高技术研究发展基金项目(2003AA132050)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2005年05期
  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】142
节点文献中: 

本文链接的文献网络图示:

本文的引文网络