期刊文献+

基于数据挖掘的Snort增强模型的研究 被引量:3

Research of the Data Mining Based Snort Enhanced Model
在线阅读 下载PDF
导出
摘要 Snort是一个简单而有效的基于规则的开源入侵检测系统,但有一定的局限性。论文提出了一个基于数据挖掘的Snort增强模型以采用各种数据挖掘技术来解决Snort的某些局限,还构建了基于案例推理(CBR)的应用实例,良好地验证了模型的正确性和灵活性,且由于"自适应"的特点,该模型还具有较强的可扩展性和交互性。 The Snort is a simple and effective rule-based open source intrusion detection system.But it has some limitations.In this paper a data mining based Snort enhanced model is proposed to adopt data mining techniques to solve the limitations of the Snort.The accuracy and flexibility of the model are well verified by building a case based reasoning(CBR) application instance.The model is adaptive,so it also has scalabiliy and interactivity.
作者 李玲娟
出处 《南京邮电学院学报(自然科学版)》 2004年第4期1-5,共5页 Journal of Nanjing University of Posts and Telecommunications
基金 江苏省教育厅自然科学研究专项基金(02SJD520002)资助项目
关键词 数据挖掘 SNORT 入侵检测 Data mining Snort Intrusion detection
  • 相关文献

参考文献8

  • 1http://www.Snort.org
  • 2HAN Jiawei,KAMBER M.Data mining:Concepts and Techniques[M].San Francisco:Morgan Kaufmann Publishers,2001.
  • 3LEE Wenke,STOLFO S J, MOK K W.A data mining framework for building intrusion detection models[A]. Proceedings of the 1999 IEEE Symposium on Security and Privacy[C].1999.120~132.
  • 4MITCHELL T M. Machine Learning[M]. New York: McGraw-Hill, 1997.
  • 5LEE Wenke,STOLFO S J, CHAN P K,et al.Real time data mining-based intrusion detection[A].DISCEX '01 Proceedings[C].2001.89~100.
  • 6DUTTA S, WIERENGA B, DALEBOUT A. Case-based reasoning systems: from automation to decision-aiding and stimulation[A].IEEE Transactions on Knowledge and Data Engineering[C].1997,9(6):911~922.
  • 7BUB R,HENDERSON W, WRIGLEY D, et al.A case-based reasoning system for troubleshooting[A].IEE Colloquium on Case Based Reasoning: Prospects for Applications[C].1994.5/1~5/9.
  • 8ALESSANDRI D,CACHIN C,DACIER M,et al.Towards a taxonomy of intrusion detection systems and attacks[R].Zurich:Zurich Research Laboratory,2001.

同被引文献23

引证文献3

二级引证文献41

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部