节点文献

基于数据挖掘的入侵检测系统的研究

Study of Data Mining Based Intrusion Detection System

【作者】 陈华胜

【导师】 吕锋;

【作者基本信息】 武汉理工大学 , 通信与信息系统, 2004, 硕士

【摘要】 随着internet的飞速发展,计算机网络已经在社会、经济、文化和人们的日常生活中扮演着越来越重要的角色。人们在使用计算机网络的同时,也深深的注意到网络安全的重要性。因此,研究如何快速准确的检测出网络中入侵事件的发生,就显得尤为重要和迫切。 在当前入侵检测技术中,基于数据挖掘的入侵检测技术有较好的发展前景。它将数据挖掘的技术引入到入侵检测中来,在智能型、准确性和扩展性方面有了很大的提高。本文在一个典型的基于数据挖掘的入侵检测系统的基础上,通过对新型入侵手段和数据挖掘的研究,对基于数据挖掘的入侵检测系统进行了分析与改进。作者所做的主要工作包括: (1) 分析了一个典型的基于数据挖掘的入侵检测系统MADAMID。重点研究了系统的组成结构,工作原理以及数据挖掘算法如何在入侵检测系统中的应用。 (2) 深入的研究了数据挖掘中的关键算法—关联规则挖掘算法。将MADAMID中的算法Apriori与其它三种高速的关联规则挖掘算法进行了仔细的比较分析,并结合入侵检测应用中的实际情况,在四种关联规则挖掘算法中选出一种最适合入侵检测系统的算法—FP_Growth算法,该算法与Apriori算法相比在性能上有较大的提高。 (3) 通过对DDoS和蠕虫的入侵特征的分析,提出了在基于数据挖掘的入侵检测系统中如何快速检测到入侵以及快速响应的方法。 (4) 在原系统结构中引入了智能代理技术,提出了基于区域的入侵检测系统模型(ABID)。该模型具有以下特点:①引入区域的概念,将基于主机的入侵检测和基于网络的入侵检测结合在一起,提高了检测的准确性。② 采用分布式结构,区域间的入侵检测代理组件具有独立性,提高了处理速度和健壮性。③ 使用多层结构确保系统的组件各司其职,增强了系统的可扩展性。 (5) 提出了用户行为模式的异常检测的解决方案。采用Telnet会话纪录中的shell命令作为用户行为异常检测的数据源,用FP_Growth算法进行规则的挖掘,形成历史行为模式和当前行为模式并进行比较以实现异常检测。 本文的研究工作在入侵检测领域具有一定的理论和实用价值,可为入侵检测系统的设计提供参考

【Abstract】 With the fast development of Internet, computer network has played the more and more important role in the society, economy, culture, and people’s life. While using the computer network, people are also aware of the important of network security. So, it is urge to study how to find the intrusion in computer network precisely and rapidly.Among the intrusion detection technologies, data mining based intrusion detection technology has good prospects. It introduces the data mining to the intrusion detection, which upgrades the intelligent, veracity and expansibility of intrusion detection system. In this paper, research has done on a typical data mining based intrusion detection system, and some amelioration is put forward. The author’s main workings are given as follows:(1) The paper analyzes a typical data mining based intrusion detection system-MADAMID, takes an emphases on researching system’s framework, theory, and way that how to use the data mining in intrusion detection.(2) Research is done on the association rule mining algorithm, a important data mining algorithm. Apriori, used in MAD AMID, is compared with other three high performance association rule mining algorithms. The most efficient algorithm is chosen from four popular association rule mining algorithms by the comparison and analysis. The new algorithm outperforms the former algorithm that used in the MAD AMID system.(3) Research is done on the DDoS and worm intrusion, and the fast detecting and reacting approach is put forward.(4) Agent technology is introduced into the MADAMID system, and a new system model, area based intrusion detection system (ABID), is put forward. The characters of ABID model are as follows. (1)The concept of area is used, whichcombines the host based intrusion detection and the network based intrusion detection. So it upgrades system’s veracity. (2) Distributed framework is used. The intrusion detection agent module in area is unattached, and it upgrades the processing speed and system’s security. (3) Hierarchy is adopted, which upgrade system’s expansibility.(5) The FP_Growth algorithm is used to achieve anomaly detection. Data resource is coming from the shell command in Telnet session record. Data resource is mined by FP_Growth algorithm to build the user’s history activity model and current activity model, which is compared to achieve anomaly detection.The research in the paper has definite theoretic and practical value in the fieldof intrusion detection; it is a useful reference for designing the intrusion detectionsystem.

  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】375
节点文献中: