节点文献

基于信息融合的入侵检测模型的研究与实现

【作者】 刘理争

【导师】 柴乔林;

【作者基本信息】 山东大学 , 计算机应用技术, 2005, 硕士

【摘要】 入侵检测系统是网络安全体系的一个重要的组件。传统的完全基于神经网络的入侵检测系统难以获得丰富充足的样本。因此,目前的入侵检测系统面对不断变化和升级的网络配置缺乏可扩展性,而且面对新的攻击类型适应性不强。 本文首先介绍了入侵检测的重要性、发展历史、概念和通用框架、分类以及入侵检测的方法和技术。然后引入了信息融合的观点,用证据理论方法作为信息融合的方法,使用神经网络作为分类器,构造了一个新的入侵检测模型。 该模型使用DARPA(Defense Advanced Research Projects Agency)为1999年KDD(Knowledge Discovery and Data Mining)竞赛所建立的基本数据库作为数据源。在详细分析数据源中的41个特征后,又将攻击类型以及所属类别做了对比。从4898431条连接记录的攻击统计分布来看,4种类型攻击发生的概率相差很大,所以本文提出了一种特征筛选和排序的方法。 将经过筛选和处理过的特征作为输入向量,输入到径向基函数网络(RBF)。该模型共使用了4个径向基函数网络,分别根据基本TCP特征、内容特征、基于时间的流量特征和基于主机的流量特征将连接分为正常、DoS、R2L、U2R和Probe,并将分类结果作为证据,输入到证据理论模块。通过证据理论模块将4个RBF网络的输出融合在一起,降低了虚警率,提高了检测率。

【Abstract】 Intrusion detection is an essential component of critical infrastructure protection mechanisms. The traditional pure Artificial Neural Network (ANN) based Intrusion Detection Systems (IDSs) encounter the challenge that it is not easy for them to acquire enough abundant samples. Current IDSs thus have limited extensibility in the face of changed or upgraded network configurations, and poor adaptability in the face of new attract methods.Firstly, this thesis introduces importance, history, classification, definition and common framework of Intrusion Detection Systems and discusses intrusion detection methods and technologies. Then, it imports information fusion theory, uses evidence theory as information fusion algorithm, and uses ANN as classification to construct a new Intrusion Detection Model.This model uses dataset, created by MIT Lincoln Labs, for the 1999 KDD intrusion detection contest. After analyzing 41 features of dataset in detail, this paper compares all attack types and sorts this attacks into 4 classes: DoS, R2L, U2R and Probe. From attack breakdown of 4898431 attacks, the probabilities of 4 classes’ attacks occurrence are largely different. So a feature choosing and ranking method is put forward.Chosen and processed features input Radial Basis Function (RBF) nets as input vectors. This model uses 4 Radial Basis Function nets, which classify connections into normal, DoS, R2L, U2R, Probe according to Basic TCP features, Content features, Time_based traffic features and Host_based traffic features. Then those classified results are treated as pieces of evidence, which are the inputs of evidence theory module. Though using evidence theory module to fuse all output vectors of 4 RBF nets, false positives are decreased and the detection rate is improved.

  • 【网络出版投稿人】 山东大学
  • 【网络出版年期】2005年 08期
  • 【分类号】TP393.08
  • 【被引频次】5
  • 【下载频次】203
节点文献中: 

本文链接的文献网络图示:

本文的引文网络