节点文献
基于数据挖掘的主机入侵检测系统的设计与实现
Design and Implementation of Host Intrusion Detection System Based on Data Mining
【作者】 程冉;
【导师】 皮德常;
【作者基本信息】 南京航空航天大学 , 计算机应用技术, 2006, 硕士
【摘要】 自从计算机问世以来,信息技术得到日新月异的发展。随着信息技术的飞速发展,人类正迈入以网络为主的信息时代。越来越多的人通过Internet进行商务活动。但是由于Internet的开放性决定了网络系统的脆弱性,随之而来的安全问题也越来越突出。如何构建一个安全的网络环境,已经成为一个大家关心的热门话题。本文首先介绍了入侵检测技术的研究背景、入侵检测系统的现状,接着介绍了入侵检测技术的发展历程、入侵检测的定义、入侵检测系统的功能以及发展前景和目前入侵检测技术的局限性,然后介绍了数据挖掘的一些基本概念和算法,重点介绍了关联规则分析法,最后介绍了一个基于数据挖掘的主机入侵检测系统的设计和实现,并对系统做了总结和展望。在系统的设计和实现部分,我们把数据挖掘技术运用到入侵检测系统中,构建了一个基于数据挖掘的主机入侵检测系统,可以实时地监控进程状态、文件系统状态、CPU使用状态、内存使用状态、注册表的使用状况以及主机的网络状态,并运用了数据挖掘算法实时对它们进行分析,形成规则,以便与模式库里的规则进行匹配。最后,我们指出了主机入侵检测技术的不足之处,例如入侵检测系统的分析能力不能满足网络带宽迅速发展的需求等。
【Abstract】 Since the appearance of the computer, the technology of information has got a rapid development. With the continuously improvement of the technology of information, we are going into an information age. More people deal with business affairs by Internet. People pay more and more attention to the problem of security of information because of the Internet’s open characteristic.The paper at first introduces the background of the study on technology of intrusion detection, actuality of intrusion detection system, secondly, the history of development of that technology, the definition and function of intrusion detection, the foreground of intrusion detection system and the limit of the technology of intrusion detection are introduced, and then some basic definitions and arithmetic on data mining in which we emphasize the analyzing of associated rule are introduced. Lastly, this paper introduces the design and implementation of a host intrusion system based on data mining and we get a summarization of this system and give an advice about prospect. At the part of design and implementation of that system we construct an intrusion detection system based on host by the technology of data mining, and this system can real-timely monitor statuses about processes, file system, CPU, memory, register and network of host and we uses the arithmetic about data mining to analyze data about them, as a result we get some rules which can be matched with rules in pattern warehouse. Lastly, we give an advice on the limit of intrusion detection technology, such as the system’s analyzed ability can’t satisfy the requirement of the rapid development of net’s bandwidth.
【Key words】 Intrusion Detection; Host; Information Security; Data Mining; Rule Pattern;
- 【网络出版投稿人】 南京航空航天大学 【网络出版年期】2006年 10期
- 【分类号】TP393.08
- 【下载频次】213