节点文献

Agent和神经网络相结合的入侵检测系统研究

The Research of Distributed Intrusion Detection System Based on the Agent and Neural Network

【作者】 李明

【导师】 程显毅;

【作者基本信息】 江苏大学 , 计算机应用技术, 2008, 硕士

【摘要】 随着计算机技术和网络技术的迅速发展,针对计算机和网络的攻击也逐渐增多,手段也变得更加复杂和隐蔽,安全问题越来越受到人们的重视。相对于防火墙和数据加密来说,入侵检测是一种主动的安全防御措施,能够在更大程度上保护用户信息安全,但是现有的入侵检测系统仍有诸多缺陷:首先是无法应对高速传输速率和海量数据;其次,不能及时有效地检测出变异的攻击或新型的攻击手段。这些问题严重制约了入侵检测系统的发展和普及。本文在对IDS(Intrusion Detection System)进行系统的研究的基础上,对神经网络和Agent在入侵检测系统中的应用现状进了深入的分析,主要进行了以下工作:(1)基于入侵检测通用框架(CIDF,Common Intrusion Detection Framework)提出了Agent和神经网络相结合的入侵检测模型IDS-AN(Intrusion DetectionSystem based on the integration of Agent and Neural network)。按照CIDF框架设计不同的代理,通信协议采用一套严格定义的通信规则和数据格式(GIDOGeneralized Intrusion Detection objects)。各种功能的Agent和MA平台有着标准的协商协议,代理可以进行动态创建。(2)提出了NN(神经网络Neural Network)和Agent相结合的检测方式。Agent主要采用基于规则的检测方式,对己知的攻击可得到较好的检测效果;NN主要采用基于异常的检测方式,对于具有新的特征的攻击在一定范围内可检测出来。把它们的优势相结合,来确保最大的检测准确性,尽可能地降低漏报率和误报率。(3)针对神经网络收敛速度慢的问题,降低了求权的次数,并设计了自适应动量项。基于改进的BP神经网络设计入侵检测Agent(IDA Intrusion DetectionAgent)。采用网络数据包或日志为数据源,BP神经网络先经过训练,再对输入的向量进行判别,以判断出是否是攻击行为,使得IDA具有自治和自适应的特性。(4)对IDA进行了标准化。各种功能的Agent和MA平台采用标准的通信接口通信,因此,它们的设计为系统的分布式部署和系统的扩充性实现做了充分的考虑,同时入侵检测层可有基于不同神经网络的IDA,不同IDA的功能更加单一。功能的单一性带来的好处是使得对某一种入侵行为的检测趋于标准化。同时,每一个代理功能的加强都不会影响系统的其他部分。由于各个代理有着标准的通信协议接口,这样大大减小了系统各个部分之间的通信量。为了检验IDS-AN模型的效率,使用LiBPcab/TCPdump获得现场数据,利用BP神经网络设计的入侵检测单元,通过使用神经网络的入侵检测Agent与未使用神经网络的入侵检测Agent实验对比,前者在误报率、漏报率有一定的改善。

【Abstract】 With the computer technology and the development of Internet technology, the attacks for computer and network have increased gradually, whose means have become more and more complicated and concealed, and the security issues are getten increasing attention. Compared with the firewall and data encryption, intrusion detection is a pro-active measures of security, to the greater extent, which can protection user’s information security.but the intrusion detection system still has many shortcomings: Firstly,it can not hold high speed and infinite date. Secondly,it cannot detect the attacks of variation or new means of attack.These problems are seriously hindering the development of intrusion detection system.In this paper, base on the research of IDS (Intrusion Detection System) system. the neural network and the application situation of Agent in IDS are analysed in detail,mainly as following work:(1) Based on CIDF,propose a intrusion detection model IDS-AN,which is the combination of Agent and the neural network.According to CIDF,design many different agents,and communication protocol adopts a set of strictly defined communication rules and data formats(GIDO).The Agent and MA platform with various functions have the normative consultation agreement,and agents can be created dynamically.(2) Put forward a new detection method with the combination of NN(neural network) and Agent.Agent mainly uses rule-based detection method,so known attacks can be detected effectively. NN mainly uses abnormity-based detection method,so the attacks with the new feature can be detected in a certain scope.To ensure maximum detection accuracy,their advantages are combined to reduce the rate of omission and the rate of misinformation as far as possible.(3) Design the adapting momentum term,in the light of the slowly convergence speed of BP neural network,and reduce the number of making weight.Design intrusion detection Agent based on BP neural network. By adopting the network data and log as the data source,BP neural network is trained firstly,then discriminations the vector for importation,to judge whether the attacks are existent,and makes IDA’characteristics autonomy and self-adaptive.(4) Standardize the IDA.The Agent and MA platform with various features use commucication interface to communicate,therefore,they are designed for the sake to the system of distributed deployment and expansive implement, and intrusion detection layer has neural network based on IDA,and the functions of different IDA are much more single,which bring the benefits of making a certain kind of intrusion detection tend to standardization.At the same time,the strengthening of every Agent’function will not affect other parts.Since each Agent has a standard communication protocol interface,the communication quantities among various parts are reduced greatly.In order to the efficiency of IDS-AN model,use Libpcab/TCPdump to gain scene data,use the intrusion detection module designed by the BP nenural network,and through the contrastive experiment between the intrusion detection Agent with neural network and the intrusion detection Agent without neural network,the former has some improvement on the rate of omission and the rate of misinformation.

【关键词】 入侵检测分布式AgentBP神经网络IDS-AN
【Key words】 入侵检测分布式AgentBP神经网络IDS-AN
  • 【网络出版投稿人】 江苏大学
  • 【网络出版年期】2008年 09期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】157
节点文献中: