节点文献

基于数据挖掘的网络入侵检测方法的研究

Research on the Method of Network Intrusion Detection Based on Data Mining

【作者】 翟素兰

【导师】 郑诚;

【作者基本信息】 安徽大学 , 计算机应用技术, 2005, 硕士

【摘要】 入侵检测系统的出现使网络信息安全的保护从被动走向主动,这样在网络防火墙基础上又增加了一道兼顾局域网内外的防护网。但是计算机系统的复杂化和网络数据的海量化,给安全审计网络数据带来极大的困难,数据挖掘技术的出现和机器学习理论的发展提供了解决这个问题的有效手段。我们可以从网络海量数据中开发出入侵检测模型。它的研究具有重大的理论和现实意义。 本文主要从数据挖掘的角度对网络数据进行分析,挖掘出入侵检测模型,用于入侵检测。 第一章绪论,回顾了网络安全的现状,讲述了计算机信息安全的一些概念,以及入侵检测研究的必要性,和数据挖掘的概念分类方法等内容。论述了基于数据挖掘的入侵研究的必要性和可行性。 通过使用数据挖掘和机器学方法得到入侵检测的模型,进行入侵检测是本文的重点部分,主要有以下内容: 第二章基于粗糙集的属性选择。网络侦听审计数据极其丰富,包括大量冗余信息,这不仅使生成入侵检测模型的代价过高,对于某些方法还是不可能的。本文对KDD99数据的约简上使用了粗糙集理论。经过约简,属性间的独立性得到了保证。这是朴素贝叶斯分类器使用的前提。 第三章贝叶斯分类器用于误用检测。在粗糙集约减的基础上,使用朴素贝叶斯分类器对KDD99数据进行学习和分类,将实验结果同决策树学习进行了比较。由于入侵检测系统不仅要保证一定的准确率,而且还应在此条件下考虑误报所带来的风险。本文又提出了使用基于最小风险的贝叶斯分类器用于入侵检测的方法。 第四章改进权值树并将其用于异常检测。本文使用的系统调用序列的短序列作为系统的正常库。根据系统调用的短序列首先生成权值树森林,后进行基于海明距离的剪枝。以此作为数据结构进行入侵检测,检测的过程中利用了检测经验同时也注意经验的更新。使用改进的权值树进行入侵检测,不仅可以检测出新的入侵行为,而且提高了入侵检测的时效性。

【Abstract】 Intrusion Detection System (IDS) bring network information security from passive to positive.Thus ,IDS provides local network security not only on inside but alse on outside. Owing to complication of computer system and great magnitude of network audit datas, it is difficult to audit data from network. With the development of Data Mining and machine learning theory,IDS model can be drawn form the audit data.The thesis focuses on analysis the audit data using data mining technolgy,and draws IDS model.In chapter 2nd,the magnitude of network audit datas is great. Audit data contains a great deal of redundancy.The cost of making training data is high and difficult to achive.To solve the problem ,a new method is introduced. Rough Set-base Reduction is combined with naive bayes.Rought Set _base Reduction have firm mathematics base .The reduction dosen’t request knowledge of background and meet stand of Data Mining.In fact The independence of featers must be achived before using naive bayes.In chapter 3rd, Bayes network is used in IDS. Naive Bayes is a very simple form of Bayes network and particularly efficient for inferenece tasks.But it is based on a very strong independence assumption.The chapter offers an experimental study of the use naive Bayes in intrusion detection .The experiments show that the simple structure provides very competive results comparing with one of well known maching learning techniques which is decision tree.Moreover we introduces bayes based on the least minmum risk in IDS. The experiment shows good results.All experiments are done on KDD’99 intrusion data sets reduced using Rough set.In chapter 4th,An improved method for anormly intusion detection is brough froward.The normal pattern is based on normal system callls.The structure is the weight tree based on naming distance.During intrusion detection ,scan system calls sequence using the normal weight tree and get corresponding weight sequence ,on which make decision whether it is normal or abnormal.At the same time pay attention to making good use of experience and updating experience .The balance of the cost offeature and the risk is the other work .The method not only can detect new intrusion but also can work in real live network enviroment.The main work and the feature of the paper is as follow:1. Rough Set theory is used to reduce features in a great deals of data set.So it produces feature set that has perfect independency, on which assumption Nai’ve Bayes is based.2. Using Bayes theory in misuse intrusion detection.The learning corrct efficiency and time efficiency can meet the needs of intrusion detecton.The use of the minimum risk theory can bring down the risk of IDS .3. Improve the weight tree and use it in abnormal intrusion detection .During detecion ,make good use of experience and balance the cost of feature and the risk of the decision.The method not only can detect new intrusion ,but also can work in live enviroment.

  • 【网络出版投稿人】 安徽大学
  • 【网络出版年期】2006年 02期
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】418
节点文献中: 

本文链接的文献网络图示:

本文的引文网络