基于可拓集的入侵检测模型  被引量:6

Intrusion detection model based on extensible set

在线阅读下载全文

作  者:肖敏[1] 柴蓉[2] 杨富平[1] 范士喜[3] 

机构地区:[1]重庆邮电大学计算机科学与技术学院,重庆400065 [2]重庆邮电大学通信与信息工程学院,重庆400065 [3]北京印刷学院计算机科学系,北京102600

出  处:《重庆邮电大学学报(自然科学版)》2010年第3期345-349,共5页Journal of Chongqing University of Posts and Telecommunications(Natural Science Edition)

基  金:国家自然科学基金(40801214)~~

摘  要:针对入侵行为特征表现的隐蔽性、不确定性和多样性问题,提出一种基于物元模型和可拓集的入侵检测模型。利用多评价特征类物元描述多特征表现的入侵行为,建立每一个评价特征的关联函数并进行运算,得到综合关联函数以建立多特征物元可拓集,作为检测该入侵行为的模型。对于待检测行为,通过计算其与可拓集的综合关联度来判定是否为入侵行为以及异常的程度,不同的综合关联函数能够实现基于多特征融合的不同检测方法,该模型被应用到网络异常流量检测中。Intrusion behavior is featured with concealment,uncertainty and diversity.An intrusion detection model based on matter element model and extensible set was introduced to meet this trend.An intrusion behavior with multiple performances was described by a class matter element with multi-evaluating features,and for each evaluating feature,a dependent function was constructed.Through a simple arithmetic,the all dependent functions were fused into an integrated dependent function,which was used to establish an extensible set detecting the intrusion behavior.For the behavior to be detected,the integrated dependent degree was calculated,which can determine whether the behavior is intrusion and can also determine abnormal degree,achieving a variety of detection methods based on multi-feature fusing.This model was implemented in network traffic anomaly detection.

关 键 词:网络安全 入侵检测 物元 可拓集 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象