首页 | 本学科首页   官方微博 | 高级检索  
     

基于改进Apriori算法的审计日志关联规则挖掘
引用本文:徐开勇,龚雪容,成茂才.基于改进Apriori算法的审计日志关联规则挖掘[J].计算机应用,2016,36(7):1847-1851.
作者姓名:徐开勇  龚雪容  成茂才
作者单位:信息工程大学, 郑州 450001
基金项目:国家自然科学基金资助项目(61072047)。
摘    要:针对安全审计系统中存在的智能程度低、日志信息没有充分利用的问题,提出一个基于关联规则挖掘的安全审计系统。该系统充分利用已有审计日志,结合数据挖掘技术,建立用户及系统的行为模式数据库,做到及时发现异常情况,提高了计算机的安全性。在传统Apriori算法的基础上提出一种改进的E-Apriori算法,该算法可以缩小待扫描事务集合的范围,降低算法的时间复杂度,提高运行效率。实验结果表明基于关联规则挖掘的审计系统对攻击类型的识别能力提升在10%以上,改进的E-Apriori算法相比经典Apriori算法和FP-GROWTH算法在性能上得到了提高,特别是在大型稀疏数据集中最高达到51%。

关 键 词:安全审计系统    审计日志    数据挖掘    关联规则挖掘    Apriori算法
收稿时间:2015-12-11
修稿时间:2016-03-21

Audit log association rule mining based on improved Apriori algorithm
XU Kaiyong,GONG Xuerong,CHENG Maocai.Audit log association rule mining based on improved Apriori algorithm[J].journal of Computer Applications,2016,36(7):1847-1851.
Authors:XU Kaiyong  GONG Xuerong  CHENG Maocai
Affiliation:Information Engineering University, Zhengzhou Henan 450001, China
Abstract:Aiming at the problem of low-level intelligence and low utilization of audit logs of the security audit system, a secure audit system based on association rule mining was proposed. The proposed system was able to take full advantage of the existing audit logs and establish the behavior pattern database of users and the system with data mining technique. The abnormal situation was discovered in a timely manner and the security of computer system was improved. An improved E-Apriori algorithm was proposed which could narrow the scanning range of the set of transactions, lower the time complexity, and refine the operating efficiency. The experimental results indicate that the lift of recognition capability to identify the type of attack can reach 10% in the secure audit system based on association rule mining, the proposed E-Apriori algorithm clearly outperforms the traditional Apriori algorithm and FP-GROWTH algorithm, and the maximum increase can reach 51% especially in the large sparse datasets.
Keywords:security audit system                                                                                                                        audit log                                                                                                                        data mining                                                                                                                        association rule mining                                                                                                                        Apriori algorithm
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号