节点文献

基于危险模型的三级模块式入侵检测系统

Danger model-based three-level-module intrusion detection system

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 赵林惠戴亚平付东梅董芳艳

【Author】 ZHAO Lin-hui~1, DAI Ya-ping~1, FU Dong-mMei~1,DONG Fang-yan~2 (1. School of Information Science and Technology, Beijing Institute of Technology, Beijing 100081, China; 2. Department of Computer Intelligence & System Science, Interdisciplinary Graduate School of Science and Engineering, Tokyo Institute of Technology, Yokohama 226-8502, Japan)

【机构】 北京理工大学信息科学与技术学院东京工业大学大学院综合理工学研究科智能系统科学专攻 北京100081北京100081日本横滨226-8502

【摘要】 利用危险理论和数据融合技术,提出一种基于危险模型的三级模块式入侵检测系统,并在第三级模块中提出了一种自适应决策模板算法,实现了检测模板的在线自动修正。系统的优点在于:对于利用现有知识难以给出检测结果的情况,系统将根据是否有危险信号做出判断,不但可减少误报还能改善对未知攻击的识别能力;利用自适应决策模板算法,系统的检测模板能够在线调整,不需要定期更新,使系统能适应行为经常改变的环境,也因此提高了检测未知攻击的能力。基于KDD-CUP-99数据库的实验验证了系统的有效性。

【Abstract】 Based on Danger theory and data fusion technology, a new Danger model-inspired three-level-module intrusion detection system was presented. Also, an adaptive decision templates algorithm was derived, realizing the online automatic regulation on detection templates. There are two characteristics of the system. First, when it is difficult to distinguish current behaviors according to the present knowledge, this system will discriminate them by means of danger signals, thus false alarms are reduced and the ability of identifying novel attacks is enhanced. Second, the adaptive decision templates algorithm allows detection templates to modify dynamically without periodical updating, which enables the system to be adapted to a changing environment, and also increases the accuracy on unknown attacks. Experimental results on test data from KDD-CUP-99 database were reported to show the effectiveness of this system.

【基金】 兵器预研支撑基金资助(YJ0467011);北京理工大学基础研究基金(BITUBF200501F4206)
  • 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2006年10期
  • 【分类号】TP393.08
  • 【被引频次】9
  • 【下载频次】122
节点文献中: 

本文链接的文献网络图示:

本文的引文网络