摘要
在引入领域(Realm)概念的基础上,提出了一种新的蜜网模型——BRHNS(Based Realm Honeynets)。BRHNS模型利用Realm之间的协作性,提高了蜜网的工作效率,其中的入侵行为分析模块,用无监督聚类的方法对未知攻击的数据进行分类预处理,为以后提取入侵规则并将新的入侵规则添加到IDS规则库中打下了基础,进而提高了IDS的检测效率,降低了蜜网的工作量。通过交叉验证的方法进行实验,发现用无监督聚类算法能够很好地对攻击数据进行分类。
Based on citing Realm,a new Honeynets Model-BRHNS is presented.BRHNS makes use of cooperation between Realms,the efficiency of Honeynets is improved.In intrusion behavior analysis module,unknown attack data are classified by the unsupervised clustering,accordingly,prepared for extracting intrusion rules and adding the new rules to IDS rule-lib,consequently, the detection efficiency of IDS is improved and the workload of BRHNS is effectively reduced.Have performed experiments through cross-validate,we find it is effective to classify the attack data by the unsupervised clustering.
出处
《计算机工程与应用》
CSCD
北大核心
2007年第7期139-143,共5页
Computer Engineering and Applications
基金
河北省自然科学基金(the Natural Science Foundation of Hebei Province of China under Grant No.F2004000133)
关键词
网络安全
诱捕
蜜网
领域
数据分析
network security
entrapment
honeynets
Realm
data analysis