期刊文献+

基于CBR技术的入侵检测系统研究 被引量:1

Research on Intrusion Detection System Based on CBR Technology
在线阅读 下载PDF
导出
摘要 目前,成熟的商用入侵检测系统都是基于特征或者规则的精确匹配,如果攻击模式过于特殊或者攻击者采用一些躲避检测的手段,就容易产生误报或漏报,从而降低入侵检测系统的准确性。针对当前入侵检测系统存在的缺陷,提出了一种基于案例推理技术(Case-Based Reasoning,CBR)的入侵检测系统模型,并在该模型基础上提出了基于Snort的预处理模型以避免推理产生的系统资源过度消耗问题;提出了基于分层结构的案例库维护模型以解决案例质量问题和访问效率问题;设计了一种基于变权值的CBR引擎搜索匹配算法以提高搜索精度。仿真实验证明了上述系统可以有效地解决躲避攻击问题,其检测正确率较传统系统有所改善。 At present, mature eommereial intrusion detection systems usually adopt precise matching based on features or rules. If an attack mode is too special or an attacker adopts some evading detection techniques, it will lead to high false positive or false negative, thereby reducing the accuracy of whole system. To solve those problems, this paper proposes an intrusion detection system model based on case-based reasoning, then puts forward the pretreatment model based on snort to avoid the problem of excessive consumption of system resources caused by reasoning, and uses layered struc- ture case base maintenance model to solve the problems of case quality and access speed, designs an improved matching algorithm based on variable weights for CBR engine to improve searching accuracy. Simulation results show that the above system can solve the problem of evading detection successfully and has been improved in detection rate compared with traditional systems.
出处 《信息工程大学学报》 2011年第3期363-368,共6页 Journal of Information Engineering University
基金 国家863计划资助项目(2009AA01A346)
关键词 入侵检测 基于案例的推理 SNORT 案例库构造 案例库维护 k-NN算法 intrusion detection case-based reasoning snort construction of case base case maintenance k-NN algorithm
  • 相关文献

参考文献7

  • 1卿斯汉,蒋建春,马恒太,文伟平,刘雪飞.入侵检测技术研究综述[J].通信学报,2004,25(7):19-29. 被引量:237
  • 2Esmaili M, Balaehandran B, Safavi-Naini R, et al. Case-Based Reasoning for Intrusion Detection[ C]//The 12th Annual Computer Security Applications Conference. 1996:214-222.
  • 3曾茹刚,管晓宏,昝鑫,郑庆华.基于案例推理的入侵检测关联分析研究[J].计算机工程与应用,2006,42(4):138-141. 被引量:2
  • 4戴成强,彭宏.CBR技术在网络入侵检测系统中的应用[J].计算机工程与设计,2007,28(8):1795-1797. 被引量:2
  • 5Qian Quan, Zhang Rui, Che Hong-Yi. Object-oriented Case Representation and Its Application in IDS [ C ]//2009 Eigth IEEE/ACIS International Conference on Computer and Information Science. 2009,10:301-306.
  • 6Rabia Alil, Maleeha Ather. Clustering Based Deletion Policy for Case-base Maintenance[ C ]//The 6th International Conference on Emerging Technologies ( ICET). 2010:45-48.
  • 7Diego P, Estevam R,Hruschka Jr,et al. Feature-weighted k-Nearest Neighbor Classifierl C ]//The IEEE Symposium on Foundations of Computational Intelligence ( FOCI 2007 ). 2007:481-486.

二级参考文献60

共引文献238

同被引文献4

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部