基于内网行为分析的未知攻击检测模型  被引量:3

Unknown attack detection model based on network behavior analysis

在线阅读下载全文

作  者:俞艺涵 付钰[1] 吴晓平[1] YU Yi-han FU Yu WU Xiao-ping(Department of Information Security, Naval University of Engineering, Wuhan 430033, Chin)

机构地区:[1]海军工程大学信息安全系,湖北武汉430033

出  处:《网络与信息安全学报》2016年第6期54-57,共4页Chinese Journal of Network and Information Security

基  金:国家自然科学基金资助项目(No.61100042);湖北省自然科学基金资助项目(No.2015CFC867);信息保障技术国防重点实验室基金资助项目(No.KJ-13-111)~~

摘  要:日益增多的未知攻击手段对内网造成安全威胁,提出了一种基于内网行为分析的未知攻击手段检测模型。借助对内网信息资源充分可知的优势,首先,收集内网信息资源资料;然后,分析内网信息节点的行为异常风险要素;最后,以信息节点与信息资源获取路径为要素构建检测有向图模型。通过验证,该模型可以达到预期的检测效果。As for the intranet security threats of the increasing number of unknown attacks, an unknown attack de- tection model based on network behavior analysis was proposed. With the help of the information resources within the intranet, firstly, the information resources of the intranet were collected, then the risk factors of abnormal behav- ior of the internet information node were analyzed, finally, the information node and the information resources ac- quisition path as the key element were used to construct the detection model of the directed graph. By verifying, the model can achieve the desired detection results.

关 键 词:内网行为 未知攻击 有向图 检测模型 

分 类 号:TP309.7[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象