节点文献
一种IDS报警可信性增强方案
Improvement scheme on creditability of intrusion detection system(IDS)
【摘要】 提高IDS(入侵检测系统)报警的可信性是IDS的根本目标。从理论上分析了可信问题产生的原因,给出了其形式化描述,提出了一种多IDS协同工作提高检测可信度的方法,并证明了该方法可以应用于各种不同IDS的协同工作中(基于误用、异常及异常与误用相结合的IDS)。多检测系统结果融合时采用推进Bayesian分类方法,给出了其模型和具体算法。实验分析表明,该方法与其他同类算法相比,降低了系统的漏报率和误报率,增强了报警的可信度。
【Abstract】 False positive rate and false negative rate affected the detection creditability of intrusion detection systems(IDS).This paper presented a method of multi-IDS cooperation to improve detection creditability after analyzing false negative rate and false positive rate of IDS.The result fusion based on boosting Bayesian classification algorithm,which put different weights on single IDS and sum the result,then choose the greatest one.The experiments show that the method can reduce the false positive rate and false negative rate,and then improve the detection creditability.
【Key words】 intrusion detection system(IDS); creditability; boosting Bayesian;
- 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2009年09期
- 【分类号】TP393.08
- 【被引频次】2
- 【下载频次】55