节点文献

一个基于免疫原理与粗糙集理论的入侵检测模型

An Intrusion Detection Model Based on Immune and Rough Sets Theory

【作者】 蒋世忠

【导师】 杨天奇;

【作者基本信息】 暨南大学 , 计算机应用, 2005, 硕士

【摘要】 随着计算机应用越来越广泛,各种安全问题层出不穷。目前,已经采用了许多措施来保护计算机系统的安全,但这些都属于静态防护措施,难以满足复杂多变的应用环境,入侵检测系统因其能提供有效的动态保护功能而成为研究热点。 现在,已经存在许多通过监视进程的系统调用序列来检测入侵的方法和模型,但这些方法普遍需要完备的调用数据来建立正常行为模式,缺乏对已知入侵的快速检测能力,难以满足实时检测的要求等问题。 针对目前基于系统调用的入侵检测方法中存在的问题,论文提出了一个基于免疫原理与粗糙集理论的入侵检测模型。首先,利用粗糙集理论能从小样本中提取出有效规则的特点,从正常系统调用序列中抽取出小部分数据,转换为决策表形式,然后利用约简理论对决策表进行约简,在约简的基础上提取出简洁的预测规则,形成正常行为模式,通过正常行为模式实现对系统调用的异常检测。受免疫记忆和人工主动免疫的启发,论文提出了一种基于免疫记忆的已知入侵的快速检测方法。 论文提出的模型不仅具有从部分系统调用中提取规则的能力,而且所得到规则形式简洁,更适应在线检测的要求,同时实现了对已知入侵行为的快速检测。初步实验表明,论文提出的入侵检测模型是切实可行的。

【Abstract】 With the application of computer becoming more and more wide, sorts of security matters emerge endlessly. In order to solve the problem, many kinds of measures protecting the security of computer system have been adopted now, but all the measures belong to static measures and can not adapt to the complicated environment of application. Intrusion detection system has become the research hotspot because it can provide dynamic protection for computer system.Many approaches have been suggested and various systems have been modeled to detect intrusions from anomalous behavior of system calls as a result of an attack, but these methods need complete system call data to build the normal behavior model. Besides, it cannot detect the known intrusion quickly and meet the requirements of real-time detection.Aiming at the problems existed in above methods or models, an intrusion detection model based on immune and rough sets is presented in this paper. The model uses the mechanism that differentiates between "self and "non-self inspired by immune system to detect intrusion. A little data is extracted from normal system call sequences and is transformed to decisive table, afterward, the decisive table is reduced and simple rules that present normal behavior mode be extracted from reduct by rough sets theory. These rules can be used to detect anomalous behavior.In order to realize the quick detection, the concept of quick detection method inspired by immune memory of immune system and artificial immune of immunology is presented.The model presented in this paper is not only able to extract a set of detection rules with the minimum size from part of record of system call sequences, but also can detect the known intrusion quickly. Preliminary experiments suggest this method is feasible and effective.

  • 【网络出版投稿人】 暨南大学
  • 【网络出版年期】2006年 01期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】178
节点文献中: