摘要
针对基于RBR技术的网络入侵检测系统中存在的误报和漏报问题,提出一种基于CBR技术的网络入侵检测系统构建方法,并对系统实现中的关键问题进行分析研究,包括系统结构设计,入侵案例的表示,案例检索与匹配等,最后采用实验数据对系统进行测试并给出结果。
Aimed at The false alarms and high detection failures based on RBR technique, a new NIDS based on CBR technique is put forward. In the mean time, key issues regarding the realization of the system is analyzed and studied, including the construction and design of the system, the representation of intrusion cases, as well as case indexing and matching, etc. Finally, the system is tested by adopting the experiment data, and the result is given.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第8期1795-1797,共3页
Computer Engineering and Design
基金
广东省科技攻关基金项目(B10101033
A10202001)
广州市科技攻关基金项目(2006Z3-D3051)
关键词
案例推理
规则推理
网络入侵检测
案例表示
案例改写
case-based reasoning
role-based reasoning
network intrusion detection
case representation
case revise