节点文献

面向电力信息系统日志数据的注入攻击特征提取方法

INJECTION ATTACK FEATURE EXTRACTION METHOD FOR LOG DATA OF POWER INFORMATION SYSTEM

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 殷博; 朱静雯; 刘磊; 许静;

【Author】 Yin Bo;Zhu Jingwen;Liu Lei;Xu Jing;State Grid Tianjin Electric Power Company;College of Software, Nankai University;College of Artificial Intelligence, Nankai University;

【机构】 国网天津市电力公司; 南开大学软件学院; 南开大学人工智能学院;

【摘要】 电力数据安全随着电力信息网与互联网的接入变得尤为严峻,其数据与规模愈加庞大复杂。为了对其进行有效的安全分析及特征提取,提出一种基于特征提取的SQL注入攻击检测模型。从Web访问日志中提取SQL注入语法特征和行为特征,得到语法特征矩阵和行为特征矩阵数据集。以漏报率和误报率为评价指标,选取K-means、Naive Bayes、SVM和RF算法分别在两类数据集上实验。实验结果表明,与以语法特征矩阵作为数据集相比,行为特征矩阵在SQL注入攻击检测中具有更好的效果。此外SVM和RF检测效果较好,具有较低的漏报率和误报率,该方法能有效检测出SQL注入攻击。

【Abstract】 Power data security becomes especially important with the access of power information network and Internet. Its data and scale become more and more huge and complex. To effectively perform security analysis and feature extraction, a SQL injection attack detection model based on feature extraction is proposed. SQL injection syntactic feature and behavioral feature were extracted from the Web access logs, and two types of data sets were obtained for syntactic feature matrix and behavioral feature matrix. Based on the evaluation index of false positive rate and false negative rate, K-means, Naive Bayes, SVM and RF algorithms were selected to experiment on two types of data sets. The results show that the behavioral feature matrix has a better effect in SQL injection attack detection than using the syntactic feature matrix as the data set. In addition, the detection effect of SVM and RF is better, with lower false negative rate and false positive rate. The method proposed in this paper can effectively detect SQL injection attacks.

【基金】 国家电网公司总部科技项目(SGTJDK00DWJS1900105)
  • 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2021年03期
  • 【分类号】TP393.08;TM73
  • 【被引频次】1
  • 【下载频次】103
节点文献中: 

本文链接的文献网络图示:

本文的引文网络