节点文献

基于D-S证据理论的网络异常检测方法

A Network Anomaly Detector Based on the D-S Evidence Theory

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 诸葛建伟王大为陈昱叶志远邹维

【Author】 ZHUGE Jian-Wei+, WANG Da-Wei, CHEN Yu, YE Zhi-Yuan, ZOU Wei (Institute of Computer Science and Technology, Peking University, Beijing 100871, China)

【机构】 北京大学计算机科学技术研究所北京大学计算机科学技术研究所 北京100871北京100871

【摘要】 网络异常检测技术是入侵检测领域研究的热点内容,但由于存在着误报率较高、检测攻击范围不够全面、检测效率不能满足高速网络实时检测需求等问题,并未在实际环境中得以大规模应用.基于D-S证据理论,提出了一种网络异常检测方法,能够融合多个特征对网络流量进行综合评判,有效地降低了误报率和漏报率,并引入自适应机制,以保证在实时动态变化的网络中的检测准确度.另外,选取计算代价小的特征以及高效的融合规则,保证了算法的性能满足高速检测的要求.该方法已实现为网络入侵检测原型系统中的异常检测模块.通过DARPA1999年IDS基准评测数据的实验评测表明,该方法在低误报率的前提下,达到了69%的良好检测率,这一结果优于DARPA1999年入侵检测系统评测优胜者EMERALD的50%检测率和同期的一些相关研究成果.

【Abstract】 Network anomaly detection has been an active research topic in the field of Intrusion Detection for many years, however, it hasn’t been widely applied in practice due to some issues. The issues include high false alarm rate, limited types of attacks the approach can detect, and that such approach can’t perform real-time intrusion detection in high speed networks. This paper presents a network anomaly detector based on Dempster-Shafer (D-S) evidence theory. The detector fuses multiple features of network traffic to decide whether the network flow is normal, and by such fusion it achieves low false alarm rate and missing rate. It also incorporates some self-adaptation mechanisms to yield high accuracy of detection in dynamic networks. Furthermore, light-computation features are used to develop an efficient fusion mechanism to guarantee high performance of the algorithm. On the 1999 DARPA/Lincoln Laboratory intrusion detection evaluation data set, this detector detects 69% attacks at low false alarm rate. Such result is better than the 50% detection rate of EMERALD—the winner of 1999 DARPA/Lincoln Laboratory intrusion detection evaluation, and results from other research projects.

【基金】 国家“十五”科技攻关计划;微软学者计划;IBM 博士生英才计划~~
  • 【文献出处】 软件学报 ,Journal of Software , 编辑部邮箱 ,2006年03期
  • 【分类号】TP393.08
  • 【被引频次】153
  • 【下载频次】1770
节点文献中: 

本文链接的文献网络图示:

本文的引文网络