节点文献

基于神经网络理论的实时入侵检测技术研究

Research on Real-time Intrusion Detection Technique Based on Neural Network Theory

【作者】 余勇

【导师】 陈蜀宇;

【作者基本信息】 重庆大学 , 计算机系统结构, 2004, 硕士

【摘要】 随着计算机网络的不断发展,网络的安全问题也日益突出,网络安全的一个主要威胁就是通过网络对信息系统的入侵。特别是存储的各种关键信息,经常遭受恶意和非法用户的攻击,使得这些信息被非法获取或破坏,严重者导致网络瘫痪。所以,对网络及其信息的保护成为重要课题。虽然传统的网络安全技术(如防火墙、加密技术等)有一定的防卫作用,但都属于静态安全技术范畴,静态安全技术的缺点是需要人工来实施和维护,不能主动追踪侵入者。鉴于此,能动态、主动地实现网络防卫的实时入侵检测技术日益成为网络安全领域的一个关键技术。 本文围绕基于神经网络的入侵检测技术进行研究,重点研究了如何在高速计算机网络中应用神经网络进行实时入侵检测的问题,对国外该方面的新进展进行了详细分析,并作了有益的扩展和改进,提出了几个新方法,主要工作如下: (1) 对传统的神经网络BP学习算法的改进方法进行了研究,综合运用变步长、学习速率可变策略和修正学习函数等方法,提出了一种改进型学习算法——BP-MA算法。改善了学习的效率,更适合于实时入侵检测的需要。 (2) 根据基于程序行为的异常检测技术的发展状况和不足,提出了一个基于神经网络的主机型异常检测模型。在分析了程序行为的特性后,提出在特权程序的层次上对程序行为进行监控。同时直接使用原始的系统调用数据作为神经网络的输入,省略了复杂的编码过程,减少了算法的复杂度。进而,在神经网络的设计中,提出用重训练剪枝方法降低了网络的复杂性和算法的时间复杂性,在保证实时性的条件下,提高了识别率。 (3) 针对网络带宽迅速提升而入侵检测系统在高速网络上处理速度不足的情况,提出了一种基于高速网络的实时入侵检测模型,该模型具有可扩展性、可实现性、可移植性层次结构等优点,充分发挥了神经网络并行处理的优势。提出了一种简单高效的“泛数值编码”,提高了实时性;并在神经网络探测器的设计上,提出了利用剪枝重训练方法和自学习再励神经网络,来提高对入侵攻击及其变体的识别能力,实验证明该网络能够不断学习新的知识,从而对入侵变体具有较高检测率。通过大量的网络通信与入侵攻击数据包的验证,说明了该模型在高速网络实时入侵检测中的有效性。

【Abstract】 Along with the progressive development of computer network technology, the security problem of network is becoming increasingly important. A primal intimidation of network security is that hackers intrude into information system through network. Especially, different kinds of key information stored in computer network often suffer the attacks by malice and illegal users, so as to, these information is acquired or destroyed illegally, even result in the network paralysis. So, the protection of network and it’s information is becoming important topic. Conventional network security techniques( such as firewall, encryption technique etc)have limited defense effects, but all of them belong to the category of static security techniques, their main drawback is that their implementation and maintenance need manual work, and cannot actively follow intruder. In consideration of this, real-time intrusion detection technique that be able to dynamically , actively realize network defense is becoming one critical technology in the field of network security day by day.The thesis emphasizes on researching how to apply neural network in real-time intrusion detection for high-speed computer network. We circumstantially analyzed the new evolvement in this field, gave some beneficial spreads and improvement, and raised several innovation. Our main job lists as follows:(1) We researched conventional neural network BP learning algorithm, by synthesizing changing-step, learning-rate-changeable-policy and amending-study -function, we proposed one kind of modification study algorithm - BP-MA algorithm, hugely ameliorated the efficiency of study, so, our algorithm is more suitable for the demand of real-time intrusion detection.(2) On the basis of development status and insufficiency of anomaly detection technology based on program behavior, we put forward one host-based anomaly detection model based on neural network. After analyzes the characteristics of program behavior, we present the thoughts to monitor program behavior on the degree of privileged program. At the same time, we directly employ the raw data as the import of neural network, and omit the complex coding process, thereby simplify the algorithm complexity. In the design of neural network, we adopt Repeatedly-drilling& Cutting-branch means to reduce the complexity of NN and the time complexity of algorithm, improved the recognition rate of NN without depressing the real-time quality.(3) The intrusion detection system based on host integrated with IDS based on network can supply more comprehensive protection to the overall system, in this dissertation, we aim at the situation that the network bandwidth rapidly exalt whereas the processing speed of IDS on high speed network is scant, present a type of real-time intrusion detection model based on high-speed network. This model possesses extensibility, realizability, portability, hierarchical tructure etc merits, give full play to the predominance of NN’s parallel processing. In order to attain the real-time demand, to the neural network input vector handle, we proposes one easy and highly-efficient encoding method: " extensive numeric encoding ". What’s more, in the design of NN detector, we pose the Repeatedly-drilling&Cutting-branch training method and Self-studying&Re-encouraged neural network to improve the recognition capability to intrusion attack and variant, and the experimental evidences indicate that the network can continually study new knowledge, thereby it possesses higher detection-rate to intrusion variant. In the meantime, by large numbers of practical network communication and intrusion offensive data packets, we validated the validity of this model in real-time intrusion detection for high-speed network.Last of all, the dissertation summarizes the whole development work and discusses the future research in this field.

  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2005年 02期
  • 【分类号】TP393.08
  • 【被引频次】3
  • 【下载频次】287
节点文献中: