首页 | 本学科首页   官方微博 | 高级检索  
     

基于危险模型的三级模块式入侵检测系统
引用本文:赵林惠,戴亚平,付东梅,董芳艳.基于危险模型的三级模块式入侵检测系统[J].计算机应用,2006,26(10):2310-2314.
作者姓名:赵林惠  戴亚平  付东梅  董芳艳
作者单位:北京理工大学,信息科学与技术学院,北京,100081;东京工业大学,大学院综合理工学研究科,智能系统科学专攻,日本,横滨,226-8502
基金项目:兵器科技预研基金;北京理工大学校科研和教改项目
摘    要:利用危险理论和数据融合技术,提出一种基于危险模型的三级模块式入侵检测系统,并在第三级模块中提出了一种自适应决策模板算法,实现了检测模板的在线自动修正。系统的优点在于:对于利用现有知识难以给出检测结果的情况,系统将根据是否有危险信号做出判断,不但可减少误报还能改善对未知攻击的识别能力;利用自适应决策模板算法,系统的检测模板能够在线调整,不需要定期更新,使系统能适应行为经常改变的环境,也因此提高了检测未知攻击的能力。基于KDD-CUP-99数据库的实验验证了系统的有效性。

关 键 词:危险理论  危险模型  入侵检测  数据融合
文章编号:1001-9081(2006)10-2310-05
收稿时间:2006-04-03
修稿时间:2006-04-032006-06-09

Danger model-based three-level-module intrusion detection system
ZHAO Lin-hui,DAI Ya-ping,FU Dong-mei,DONG Fang-yan.Danger model-based three-level-module intrusion detection system[J].journal of Computer Applications,2006,26(10):2310-2314.
Authors:ZHAO Lin-hui  DAI Ya-ping  FU Dong-mei  DONG Fang-yan
Abstract:Based on Danger theory and data fusion technology, a new Danger model-inspired three-level-module intrusion detection system was presented. Also, an adaptive decision templates algorithm was derived, realizing the online automatic regulation on detection templates. There are two characteristics of the system. First, when it is difficult to distinguish current behaviors according to the present knowledge, this system will discriminate them by means of danger signals, thus false alarms are reduced and the ability of identifying novel attacks is enhanced. Second, the adaptive decision templates algorithm allows detection templates to modify dynamically without periodical updating, which enables the system to be adapted to a changing environment, and also increases the accuracy on unknown attacks. Experimental results on test data from KDD-CUP-99 database were reported to show the effectiveness of this system.
Keywords:danger theory  danger model  intrusion detection  data fusion
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号