期刊文献+

基于模拟数据集的字节频度入侵检测研究 被引量:3

Simulation dataset based study on byte frequency intrusion detection
在线阅读 下载PDF
导出
摘要 为解决目前网络负载异常入侵检测领域缺乏有效、针对性的测试数据集的问题,提出一种基于虚拟关键字的构造模拟网络数据集的方法。并用它对基于字节频度分布的异常检测模型进行了测试分析。实验结果表明,模拟数据集提供了一种负载内容异常程度可控的测试数据集;检测阈值和网络环境的数据特性包括数据包尺寸分布情况、异常和正常访问相对于训练数据的偏离程度等有关。单包频度分布模型相比连接模型对负载数据异常程度的变动有更好的灵敏度。 Nowadays there isn’t yet adequately competent test dataset for payload based network anomaly intrusion detection system. A simulation network dataset construction approach based on virtual keywords is proposed, and the byte frequency distribution based models are tested on it. Experiment results indicate that the method provides dataset with controllable abnormal degree; detection threshold depends on characteristic of dataset including packets length distribu-tion, deviation of normal/abnormal access to training data, etc. The single packet frequency distribution model is more sen-sitive to the alteration of abnormal degree of payload data than connection based model.
作者 翁广安
出处 《计算机工程与应用》 CSCD 2014年第12期96-99,119,共5页 Computer Engineering and Applications
基金 校级自然科学基金(No.j02005302)
关键词 模拟数据集 字节频度分布 负载异常检测 网络入侵检测系统 simulation dataset byte frequency distribution payload anomaly detection Network Intrusion Detection Sys-tem(NIDS)
  • 相关文献

参考文献8

  • 1Thorat S A,Khandelwal A K,Bruhadeshwar B,et al.Pay- load content based network anomaly detection[C]//First International Conference on the Applications of Digital Information and Web Technologies, 2008.
  • 2Zhang L,White G B.An approach to detect executable content for anomaly based network intrusion detection[C]// IEEE International Parallel and Distributed Processing Symposium, 2007 : 1-8.
  • 3Wang Ke,Stolfo,Salvatore J.Anomalous payload-based net-work intrusion detection[C]//Recent Advances in Intrusion Detection : 7th International Symposium, 2004: 203-222.
  • 4Hubballi N, Biswas S, Nandi S.Layered higher order N-grams for hardening payload based anomaly intrusion detection[C]// Proceedings of ARES' 2010,2010 : 321-326.
  • 5Mrdovic S,Perunicic B.NIDS based on payload word fre- quencies and anomaly of transitions[C]//Third International Conference on Digital Information Management, 2008: 334-339.
  • 6Mrdovic S, Perunicic B.Kerckhoffs' principle for intrusion detection[C]//13th International Telecommunications Net- work Strategy and Planning Symposium,2008.
  • 7Ingham K, Inoue H.Comparing anomaly detection tech- niques for HTTP[C]//Recent Advances in Intrusion Detec- tion, 2007.
  • 8Perdisci R, Ariu D, Fogla P, et al.MCPAd--a multiple classifier system for accurate payload-based anomaly detec- tion[J].Computer Networks, 2009,53 (6) : 864-881.

同被引文献12

引证文献3

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部