摘要
针对现有入侵检测系统的不足,根据入侵和正常访问模式的网络数据表现形式的不同以及特定数据分组的出现规律,提出按协议分层的入侵检测模型,并在各个协议层运用不同的数据挖掘方法抽取入侵特征,以达到提高建模的准确性、检测速度和克服人工提取入侵特征的主观性的目的。其中运用的数据挖掘算法主要有关联挖掘、序列挖掘、分类算法和聚类算法。
Facing at the shortage in intrusion detection systems, based on the different data forms and special rules that intrusion and normal access patterns appear. An intrusion detection system modes is put forward according to protocol hiberarchies. In this mode using different data mining algorithms in different protocol hiberarchies, intrusion features were got to improve the intrusion detection system speed and overcome the shortage manual pick-up features. There are several algorithms: association, sequential, classification, clustering.
出处
《计算机工程与设计》
CSCD
北大核心
2005年第7期1701-1703,1826,共4页
Computer Engineering and Design
基金
国家自然科学基金项目(60273075)。
关键词
入侵检测
协议分析
模式匹配
数据挖掘
intrusion detection
protocol analysis
pattern matching
data mining