节点文献

基于FP-Growth和SLIQ算法的入侵检测技术研究

The Research on Intrusion Detection Techniques Based on FP-Growth and SLIQ

【作者】 孙志强

【导师】 姚跃华;

【作者基本信息】 长沙理工大学 , 计算机应用技术, 2006, 硕士

【摘要】 计算机网络安全已引起了人们的广泛关注。传统的采用认证、授权、加密和访问控制等机制的安全保护类技术不能阻止利用计算机软硬件系统的缺陷闯入未授权计算机系统的行为,而防火墙技术也不能对付层出不穷的应用设计缺陷和通过加密通道的攻击,网络中还需要有一种能够及时发现并报告系统入侵的技术,即入侵检测。入侵检测作为网络防护的重要技术,已经成为网络安全的热门研究方向。目前国际上比较前沿的入侵检测技术是把数据挖掘技术应用到入侵检测系统中,从而设计一个高效、安全的入侵检测系统。基于上述研究背景,本文在公共入侵检测框架CIDF(Common Intrusion Detection Framework)的基础上,提出应用数据挖掘技术实现入侵模式的自学习方法,有效解决了入侵检测系统在检测速度和数据集规模上存在的问题,使该系统具有较好的适应性和扩展性。文中首先参考公共入侵检测框架设计了基于数据挖掘技术的入侵检测建模方案,提出使用该技术建立入侵检测描述性模型和分类模型的思想;其次,将FP-Growth(Frequent-Pattern Growth)算法应用到入侵检测系统中,根据算法的特点并结合入侵检测领域的知识对算法进行了扩展和改进。改进后的算法能够有效的挖掘出数据的关联模式,提高算法的检测速度;最后采用SLIQ(Supervised Learning In Quest)算法进行入侵检测分类。SLIQ算法使用了预排序、广度优先等技术来解决海量数据集分类问题,在保证精度的同时提高了检测速度。实验结果表明采用这两种方法进行入侵检测是有效的,达到了提高入侵检测质量的目的,具有较广泛的应用价值。

【Abstract】 Network’s security has caused people’s extensive attention. Traditional safe protection technologies which adopts identification, authentication, access controlling, cryptography and so on can’t prevent the intrusion behavior which intrudes into the unauthorized computer system by utilizing computer defects of software and hardware of system, and the technique of the fire wall can not deal with the endless defects of application designing and the attacks which access the encryption channel. So it’s necessary to have a technique that can find and report the system intrusion behavior in time, namely intrusion detection. Intrusion detection which is regarded as an important technique of network protection has become a popular research direction of network security. At present, the international leading and advanced intrusion detection technique is applying data mining technique to IDS (Intrusion Detection System) in order to design an intrusion detection system that is both safe and efficient.Based on the research background stated above, the data mining technique based on CIDF (Common Intrusion Detection Framework) for updating detection rule library automatically is presented in this thesis, which can solve the problem of detection speed and the scale of data set to improve the adaptability and extensibility of IDS. Firstly, according to CIDF, the thesis designs a scheme on modeling intrusion detection based on data mining and brings forward the idea of descriptive model and classified model of intrusion detection. Secondly, we apply FP-Growth (Frequent-Pattern Growth) algorithm to IDS, extend and improve it according to the characteristic of algorithm and knowledge of intrusion detection. The improved algorithm can discover association patterns of data and picks up the algorithm’s detection speed. Finally, we use SLIQ (Supervised Learning in Quest) algorithm to classify intrusion data. SLIQ algorithm uses several techniques such as pre-sorting, breadth-first growth and so on to solve the problem of large data sets classification. This algorithm picks up the detection speed, meanwhile it doesn’t reduce the precision. The experiment result shows that using these algorithms for intrusion detection is effective, which can reach the goal of improving intrusion detection quality, and has widely application value.

  • 【分类号】TP393.08
  • 【下载频次】204
节点文献中: 

本文链接的文献网络图示:

本文的引文网络