首页 | 本学科首页   官方微博 | 高级检索  
     

一种改进的IDS异常检测模型
引用本文:孙宏伟,田新广,李学春,张尔扬. 一种改进的IDS异常检测模型[J]. 计算机学报, 2003, 26(11): 1450-1455
作者姓名:孙宏伟  田新广  李学春  张尔扬
作者单位:1. 国防科技大学电子科学与工程学院,长沙,410073;北京首信集团研究院,北京,100016
2. 北京首信集团研究院,北京,100016
3. 国防科技大学电子科学与工程学院,长沙,410073
基金项目:中国普天首信集团重大科研项目 ( 2 0 0 110 2 5 )资助
摘    要:基于机器学习的异常检测是目前IDS研究的一个重要方向.该文对一种基于机器学习的用户行为异常检测模型进行了描述,在此基础上提出一种改进的检测模型.该模型利用多种长度不同的shell命令序列表示用户行为模式,建立多个样本序列库来描述合法用户的行为轮廓,并在检测中采用了以shell命令为单位进行相似度赋值的方法.文中对两种模型的特点和性能做了对比分析,并介绍了利用UNIX用户shell命令数据进行的实验.实验结果表明,在虚警概率相同的情况下改进的模型具有更高的检测概率.

关 键 词:IDS 入侵检测系统 异常检测模型 计算机网络 网络安全 机器学习
修稿时间:2002-06-20

An Improved Anomaly Detection Model for IDS
SUN Hong-Wei ),) TIAN Xin-Guang ),) LI Xue-Chun ) ZHANG Er-Yang ) ). An Improved Anomaly Detection Model for IDS[J]. Chinese Journal of Computers, 2003, 26(11): 1450-1455
Authors:SUN Hong-Wei )  ) TIAN Xin-Guang )  ) LI Xue-Chun ) ZHANG Er-Yang ) )
Affiliation:SUN Hong-Wei 1),2) TIAN Xin-Guang 1),2) LI Xue-Chun 2) ZHANG Er-Yang 1) 1)
Abstract:The application of machine learning technique to anomaly detection acts as one of the important directions of research on IDS. This paper introduces an user behavior anomaly detection model based on machine learning originated mainly by Terran Lane. Then it presents an improved anomaly detection model. It uses shell command sequences of variable lengths to represent user behavior patterns and construct more than one libraries of command sequences to represent normal user behavior profiles. While performing detection, the model mines behavior patterns in the stream of shell command sequences generated by the current user, and evaluates the similarity for each shell command according to the length of the sequence, i.e. the behavior pattern which it belongs to. The similarities of the commands are then filtered and act as the measure to determine whether the behavior of the current user is noamal or not. The performance of the model is tested by computer simulation with UNIX users' shell command data. The results show it has higher detection accuracy than Terran Lane's model.
Keywords:IDS  machine learning  anomaly detection  similarity
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号