节点文献

一种基于序列挖掘的网络入侵检测新方法

Novel network intrusion detection algorithm based on sequence data mining

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 赵欣叶茂朱莺嘤郑凯元

【Author】 ZHAO Xin,YE Mao,ZHU Ying-ying,ZHENG Kai-yuan School of Computer Science and Engineering,University of Electronic Science and Technology of China,Chengdu 610054,China

【机构】 电子科技大学计算机学院

【摘要】 网络入侵检测是信息安全重要的研究问题。近年来,这方面的研究取得了很多很好的成果,但大部分方法面临检测率不高的特点。基于异常的入侵检测通常是人为选择网络连接属性,这些属性在正常和异常时具有比较明显的区别,以此来判断未知的网络连接正常与否。该方法具有一定的随机性,从而影响检测率。首先提出一种基于正常网络连接序列内在规则的属性选择算法,实现属性选择的自动化,并同时将多维序列压缩到一维序列;其次使用序列挖掘的方法训练网络连接得到正常规则库,然后利用正常网络连接规则库判断新的网络连接是否正常;最后,在KDD99数据集上进行试验,结果显示,算法检测率较高。

【Abstract】 Network intrusion detection is an important aspect of information security.Many good results in this aspect have been obtained in recent years.Most of them face the problem of low detection rate.The network connection’s attributes which have the character of obvious distinction between normal and abnormal are often chosen by experts to judge whether the new network connections are normal.This method has some randomness which affects the detection rate.A method which aims to choose attributes based on the inherent law of normal network connections is proposed.The attributes can be chosen such that the high dimensional data can be transformed to one dimension automatically.The method of sequence data mining is used to find the rules of normal network connections.The new network connections can be detected by these rules.An experiment has been done on the datum of KDD99.The result indicates that the method of this paper has high detection rate.

【基金】 国家自然科学基金No.60702071;四川省科技厅应用基础研究基金No.2006J13~065;教育部新世纪优秀人才支持计划No.NCET-06-0811~~
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2010年05期
  • 【分类号】TP393.08
  • 【被引频次】6
  • 【下载频次】199
节点文献中: 

本文链接的文献网络图示:

本文的引文网络