节点文献

基于SVM的网络入侵检测研究

【作者】 曹宏鑫

【导师】 张宏;

【作者基本信息】 南京理工大学 , 模式识别与智能系统, 2004, 硕士

【摘要】 本文将支持向量机(SVM)技术应用于网络入侵检测,在公共入侵检测框架(CIDF)的基础上,提出了基于SVM的网络入侵检测系统模型,并对模型各个组件的功能、机制、实现进行了深入探讨。对用于入侵检测的网络数据特征,本文利用异构数据集上的距离度量函数HVDM进行了特征数据的预处理,并在有保证的估计方法的基础上进行了训练数据规模的确定,既避免了因训练数据规模过小而导致的训练结果太差问题,又减少了训练时间,提高了训练效率。在训练数据的过程中,本文运用模糊数学理论,考虑不同的网络数据特征对入侵检测结果的影响程度,提出了一种加权处理方法,并通过实验数据说明该方法在检测精度上有所提高。对由于样本的不均衡性而导致的某一类型攻击的检测率偏低问题,本文也作了相应研究,提出一种提高其在训练数据中比例的方法,使这一类型攻击的检测率得到很大提高。

【Abstract】 In this paper, support vector machines (SVM) is applied to network intrusion detection. Based on Common Intrusion Detection Framework (CIDF), a framework of SVM based Network Intrusion Detection System is proposed. The function, mechanism and realization of the components of this framework are discussed in the thesis. By means of HVDM distance metric of heterogeneous datasets, the feature data of network are preprocessed. Based on guaranteed estimators, we estimate the size of test set. Thus we not only avoid bad train result for lack of examples, but also reduce the training time and improve the efficiency of training. During the training, by means of fuzzy mathematics, considering the effect of different network data features to the classification, a weight method is brought forward. It improves the accuracy of network intrusion detection. The problem of low detection accuracy of some types of attacks for the imbalance of training examples is researched. A method of increasing the proportion of the examples of these types of attacks is presented. It improves the detection accuracy of these types of attacks.

  • 【分类号】TP393.08
  • 【被引频次】14
  • 【下载频次】388
节点文献中: 

本文链接的文献网络图示:

本文的引文网络