首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于遗传算法的误用检测模型自适应建立算法
引用本文:关健,刘大昕.一种基于遗传算法的误用检测模型自适应建立算法[J].哈尔滨工程大学学报,2004,25(1):80-84.
作者姓名:关健  刘大昕
作者单位:哈尔滨工程大学,计算机科学与技术学院,黑龙江,哈尔滨,150001;哈尔滨工程大学,计算机科学与技术学院,黑龙江,哈尔滨,150001
摘    要:传统入侵检测系统的攻击模型库需要专家手工建立,不利于系统的推广和应用.为了实现入侵检测系统中入侵特征提取和攻击规则生成的自动化,提出将遗传算法应用于入侵检测规则学习问题中.采用遗传进化操作启发式搜索网络特征数据空间,通过操作算子进行遗传运算,产生出具有高适应度的个体,从而自动归纳出某种入侵的共同属性.采用DARPA入侵检测评价计划数据库进行了仿真实验,该方法归纳总结出的攻击特征符合客观事实,与专家建立的攻击规则一致,并且较好地处理了噪音数据,具有鲁棒性.误用检测模型自适应建立算法能够在无专家参与的情况下自动建立攻击类型库,增强了入侵检测系统的可移植性.

关 键 词:入侵检测  归纳学习  遗传算法  网络安全
文章编号:1006-7043(2004)01-0080-05
修稿时间:2003年2月24日

Study of building misuse detection models based on genetic algorithms
GUAN Jian,LIU Da_xin.Study of building misuse detection models based on genetic algorithms[J].Journal of Harbin Engineering University,2004,25(1):80-84.
Authors:GUAN Jian  LIU Da_xin
Abstract:The attack model bases of traditional intrusion detection systems were manually built,hampering the popularization and application of IDSs.A study was conducted to realize the automation of intrusive feature extraction and attack rule generation.An adaptive method based on genetic algorithms was presented for learning the intrusion detection rules.This approach used heuristic search in the data space of network features.The genetic operations run through some operators.The individuals with high fitness were produced,and the same attributes of an intrusion were found.In the simulations and experiments the features of an attack were summarized inductively through the databases of the DAPRA Intrusion Detection Evaluation Program,and it accorded with the objectivity and attack rule summarized by research experts.This method dealt with the noise data,and had the robustness.The adaptive method for building misuse detection models can automatically create the model bases of attacks,and strengthen the transplantation of IDSs.
Keywords:intrusion detection  induction learning  genetic algorithms  network security
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号