节点文献

基于数据挖掘的网络入侵检测方法研究

The Research of Network Intrusion Detection Method Based on Data Mining

【作者】 俞晓雯;

【导师】 高强;

【作者基本信息】 华北电力大学(河北) , 通信与信息系统, 2005, 硕士

【摘要】 本论文将数据挖掘技术应用到入侵检测领域,分别分析了数据挖掘中的聚类分析方法和关联分析方法在入侵检测中的应用。改进了K-means 聚类算法,并利用KDD cup 99 数据包对改进算法进行评估,结果表明该改进算法能提高入侵检测率。针对聚类分析方法的弱点,本文还提出了聚类分析结合关联分析的入侵检测方法以及基于此方法的入侵检测系统模型。先利用Apriori 关联规则算法发掘已知训练集中各符号属性间的关系,建立正常行为模型和入侵模型,然后按照建立的模型对聚类的初步结果进行再次划分,以达到更佳的划分结果。最后通过对KDD cup 99 数据包的检测,表明了该检测模型在对拒绝服务攻击和端口扫描攻击获得较高检测率的同时也降低了误检率,有效解决了检测率和误检率之间的矛盾。

【Abstract】 The paper applies data mining to intrusion detection,and analyzes respectively the application of clustering analysis and association rules analysis in intrusion detection.We improve the K-means clustering arithmetic and prove that the improved clustering arithmetic can advance the detection rate through the detection of the KDD cup 99 data.The paper also presents the detection method of combining clustering analysis with association rules and the model of intrusion detection based on this method.First mine the relation of symbol attribute from the known training data through Apriori association rules arithmetic,and establish normal model and abnormal model respectively,then patition the clustering result again according to the model,so that it can reach the better result.Finally the detection of  KDD cup 99 data indicate that this detection model can detect the DoS attack and the Probing attack in a high detection rate and a low wrong detection rate,so it can resolve the contradiction of detection rate and wrong detection rate effectively.

  • 【分类号】TP393.08
  • 【被引频次】10
  • 【下载频次】357
节点文献中: