首页 | 本学科首页   官方微博 | 高级检索  
     

基于并行约简的网络安全态势要素提取方法
引用本文:赵冬梅,李红.基于并行约简的网络安全态势要素提取方法[J].计算机应用,2017,37(4):1008-1013.
作者姓名:赵冬梅  李红
作者单位:1. 河北师范大学 信息技术学院, 石家庄 050024;2. 河北省网络与信息安全重点实验室, 石家庄 050024;3. 河北师范大学 数学与信息科学学院, 石家庄 050024
基金项目:国家自然科学基金资助项目(61672206);河北省科技计划项目(15214706D)。
摘    要:网络安全态势要素选取的质量对网络安全态势评估的准确性起到至关重要的作用,而现有的网络安全态势要素提取方法大多依赖先验知识,并不适用于处理网络安全态势数据。为提高网络安全态势要素提取的质量与效率,提出一种基于属性重要度矩阵的并行约简算法,在经典粗糙集基础上引入并行约简思想,在保证分类不受影响的情况下,将单个决策信息表扩展到多个,利用条件熵计算属性重要度,根据约简规则删除冗余属性,从而实现网络安全态势要素的高效提取。为验证算法的高效性,利用Weka软件对数据进行分类预测,在NSL-KDD数据集中,相比利用全部属性,通过该算法约简后的属性进行分类建模的时间缩短了16.6%;对比评价指标发现,相比现有的三种态势要素提取算法(遗传算法(GA)、贪心式搜索算法(GSA)和基于条件熵的属性约简(ARCE)算法),该算法具有较高的召回率和较低的误警率。实验结果表明,经过该算法约简的数据具有更好的分类性能,实现了网络安全态势要素的高效提取。

关 键 词:网络安全态势  要素提取  属性重要度矩阵  粗糙集  
收稿时间:2016-11-04
修稿时间:2016-12-21

Approach to network security situational element extraction based on parallel reduction
ZHAO Dongmei,LI Hong.Approach to network security situational element extraction based on parallel reduction[J].journal of Computer Applications,2017,37(4):1008-1013.
Authors:ZHAO Dongmei  LI Hong
Affiliation:1. College of Information Technology, Hebei Normal University, Shijiazhuang Hebei 050024, China;2. Hebei Key Laboratory of Network and Information Security, Shijiazhuang Hebei 050024, China;3. College of Mathematics and Information Science, Hebei Normal University, Shijiazhuang Hebei 050024, China
Abstract:The quality of network security situational element extraction plays a crucial role in network security situation assessment. However, most of the existing network security situational element extraction methods rely on prior knowledge, and are not suitable for processing network security situational data. For effective and accurate extraction of network security situational elements, a parallel reduction algorithm based on matrix of attribute importance was proposed. The parallel reduction was introduced into classical rough set, then a single decision information table was expanded to multiple ones without affecting the classification. The conditional entropy was used to calculate attribute importance, and the redundant attributes were deleted according to reduction rules, thus the network security situational elements were extracted efficiently. In order to verify the efficiency of the proposed algorithm, the classification prediction was implemented on Weka. Compared with the usage of all the attributes, the classification modeling time on NSL-KDD dataset was reduced by 16.6% by using the attributes reduced by the proposed algorithm. Compared with the existing three element extraction algorithms (Genetic Algorithm (GA), Greedy Search Algorithm (GSA), and Attribute Reduction based on Conditional Entropy (ARCE) algorithm), the proposed algorithm has higher recall rate and low false positive rate. The experimental results show that the data set reduced by the proposed algorithm has better classification performance, which realizes an efficient extraction of network security situational elements.
Keywords:network security situation                                                                                                                        element extraction                                                                                                                        matrix of attribute importance                                                                                                                        Rough Set (RS)
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号