检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]北京交通大学计算机与信息技术学院,北京100044
出 处:《北京交通大学学报》2008年第5期116-120,共5页JOURNAL OF BEIJING JIAOTONG UNIVERSITY
基 金:北京交通大学科技基金资助项目(2006XM007)
摘 要:在入侵检测研究领域中,提高检测模型的检测率并降低误报率是一个重要的研究课题.本文提出了一种针对网络入侵检测事务流的实时动态规则生成方法.该方法解决了当前主流关联规则生成算法应用到入侵检测过程中存在的多遍扫描、大量无效规则和频繁集产生等问题.实验结果表明,文中所提出的方法在规则动态生成和对网络异常情况的检测方面都显示出比较好的性能,相对Snort入侵检测系统,平均提高10%左右的检测精度,克服了Snort系统在异常检测方面的局部缺陷.In the research of the network intrusion detection, it is an important topic to improve detection rate and reduce false positive rate. In this paper, a novel real-time and dynamical rule generation method for network intrusion detection stream was proposed. This method solves a number of problems of the popular association rules extraction method that exist in applying association rules algorithm to the intrusion detection: multi-scan;a lot of useless rules; a lot of unwanted frequent sets. Experimental results have demonstrated the good performance between building efficacious rules and detecting the abnormal attack events. Comparing the detecting accuracy and the detecting anomaly attack events with the Snort intrusion detection system, It can improve 10% or so averagely and overcome the shortage of the detecting anomaly event of the Snort system.
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.147