摘要
采用数据挖掘技术,将误用检测和异常检测相结合,对分布式防火墙日志进行入侵检测分析。实验数据及分析结果表明,通过将两种入侵检测方法相结合的方式对入侵行为具有较高检测率和较低的误报率,具有一定的实际应用意义。
A method of combining misuse detection with anomaly detection, which is based on data mining technology, is presented in this paper to analyze the intrusion for the log system in distributed firewaU. The experiment result and analysis indicate that higher detection ratio and lower misdeteeting ratio are attained by the proposed way, and it can be used in real distributed firewall.
出处
《信息技术》
2008年第8期19-22,共4页
Information Technology
基金
湖北省科技攻关项目(2004AA101C67)
关键词
分布式防火墙
日志
入侵检测
数据挖掘
distributed firewall
log
intrusion detection
data mining