节点文献
基于决策树的协议分析在入侵检测中的应用研究
Research on Protocol Analysis Based on Decision Tree in Intrusion Detection
【作者】 傅韵;
【导师】 宋明秋;
【作者基本信息】 大连理工大学 , 系统工程, 2006, 硕士
【摘要】 随着网络的不断发展,安全问题越来越多,原有的防火墙已经难以单独保障网络的安全,入侵检测系统(Intrusion Detection System)开始发挥出不可替代的作用。当前大多数入侵检测产品使用的多是基于规则的简单模式匹配技术,它们存在着资源消耗量大,误报率高以及随着网速的提高而出现丢包等问题。为了提高检测效率和降低误报率,本论文提出了一种基于决策树的协议分析入侵检测系统。应用了协议分析技术,根据协议的高度规则性,将检测空间降低为单个的域以减少搜索空间提高检测效率;同时利用决策树能生成模型并具有预测能力的特点,用决策树算法进行检测模型的构建;将决策树算法和协议分析技术有机地结合起来,用于入侵检测。本文研究了协议分析中比较前沿的应用层协议分析方法,利用决策树构建入侵检测决策树模型,并通过将捕获的网络数据在入侵检测决策树上进行遍历来实现入侵检测。最后通过实验证明系统具有较高的检测率、检测效率和可用性。 论文共分四部分。首先是文献综述和问题提出。然后,建立了协议分析模块,主要包括预处理和应用层协议分析两个部分。预处理阶段包括IP分片重组和TCP流重组。对应用层协议,主要针对HTTP、SMTP、FTP三种常用协议进行了分析。接下来,描述了决策树算法的选择及决策树算法结合协议分析在入侵检测中应用,包括入侵检测决策树的数据结构、决策树的建立过程、剪枝过程以及用决策树进行入侵检测的过程。最后,是系统实现与测试。在对基于协议分析和决策树算法的入侵检测系统的系统结构设计进行描述之后,利用KDD Cup99和MIT DARPA两种权威的专门用于入侵检测的测试数据对检测准确率、效率、可用性及直观性进行了测试,记录了测试结果。实验证明系统具有较高的检测准确率、效率和较好的可用性。
【Abstract】 With the progress of network, security problems become more and more important. However, the traditional security device fire ware is unable to defence network alone. Intrusion detection system plays an important role in supporting fire wall. The simple patten matching technology is used in most IDS products. However, it has the problem of low efficiency and high false alarm rate. In order to solve the problem, the article put forward the idea of using decision tree to realize intrusion detection system based on protocol analysis. Protocol analysis technology is used to reduce the search space into single area according to the regularity of the protocols. The forecast ability of the decision tree model that constructed by decision tree method is used. In other words, decision tree method and protocol analysis technology are combined to realize intrusion detection. The method of application layer protocol analysis technology and using decision tree method to construct intrusion detection model are explored. The process of intrusion detection is realized by traversing the decision tree. At last, the thesis proves the higher accuracy and higher efficiency of the method through experiments.The thesis is devided into four parts. The back groung of the intrusion detection research, the category and development of the intrusion detection, the latest researches at home and aboard and the existing problems in intrusion detection are discussed in the first part. Then the objectives and methods are described. In the second part, the implementation of protocol analysis is described in detail. Firstly, the preprocess module is imtroduced. Then the protocols of the application layer are analyzed specifically. At last, some attributes based on statistics are given out. In the third part, the concrete process of using decision tree to realize intrusion detection based on protocol analysis is described. It includes the structure and construction process of intrusion detection decision tree and the detection process of using the decision tree. In the fourth part, the architecture of the IDS is pictured in the beginning. Then, the experiments prove that the system has high detection efficacity, the detection accuracy and the usability.
- 【网络出版投稿人】 大连理工大学 【网络出版年期】2006年 08期
- 【分类号】TP393.08
- 【被引频次】2
- 【下载频次】248