改进关联规则挖掘算法在入侵检测中的应用  

Improved Association Rule Mining Algorithm and Its Applications in Intrusion Detection

在线阅读下载全文

作  者:陆培军[1] 吴斌[2] 黄海斌[1] 

机构地区:[1]南通大学计算机科学与技术学院,江苏南通226004 [2]南通职业大学,江苏南通226000

出  处:《计算机技术与发展》2011年第11期231-235,共5页Computer Technology and Development

基  金:江苏省高校自然基金项目(10KJB510022);南通市科技计划项目(K2010065)

摘  要:在关联规则挖掘算法中基于FP-树的FP-Growth挖掘算法在挖掘频繁模式的过程中需要递归产生大量的条件FP-树,效率不高,FP-Growth算法不太适合应用到入侵中多种要素交叉的关联关系的挖掘中。因为入侵的方法及要素很多,在检测中需要对入侵样本进行条件约束下的定量分析。文中分析入侵检测的特点,提出基于条件频繁项的频繁模式树CP-Tree以及在此树挖掘的改进算法MineCPT。分析与实验结果表明,MineCPT算法在效率和可靠性等方面比FP-Growth算法更优越,在入侵检测中取得了较好的效果。The FP-Growth algorithm based on FP-Tree needs to create a large number of conditional FP-Trees recusively in the process of mining frequent patterns. It is not efficient and not good to apply in intrusion detection, in which the association rules mining include many elements. Because the intrusion includes many methods and elements, must quantitatively analyse intrusion samples. It analyzes the features of intrusion detection, proposed a new frequent pattern tree CP-Tree based on conditional frequent-items and the improved algo- rithms MineCPT which directly mines in the tree. Theoretical analysis and experimental results show that the MineCPT algorithm is superior to FP-Growth algorithm in memory occupancy and reliability. It has achieved better results in the field of intrusion detection.

关 键 词:关联规则 入侵检测 CP-树 

分 类 号:TP312[自动化与计算机技术—计算机软件与理论]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象