首页 | 官方网站   微博 | 高级检索  
     

基于最近邻策略的入侵检测方法研究
引用本文:张艳,陶军.基于最近邻策略的入侵检测方法研究[J].计算机工程与应用,2010,46(26):72-75.
作者姓名:张艳  陶军
作者单位:1. 中国矿业大学,计算机科学与技术学院,江苏,徐州,221116
2. 东南大学,计算机科学与工程学院,南京,210096
摘    要:针对目前网络入侵检测系统中,大多数网络异常检测技术仍存在误报率较高、对建立检测模型的数据要求过高、检测率不高等问题。从用户的传输行为出发,研究体现用户行为的数据报文中的IP地址、端口号、报文类型、报文长度,对异常检测的需求、审计数据的具体特征进行分析,提出了一种基于最近邻策略的用户传输行为入侵检测算法-IDNN算法。通过仿真实验,表明IDNN算法在针对不同用户应用服务行为的入侵检测中效果明显。

关 键 词:网络安全  异常检测  用户传输行为  IDNN算法
收稿时间:2010-5-20
修稿时间:2010-7-6  

IDNN: Intrusion detection algorithm based on nearest neighbor strategy
ZHANG Yan,TAO Jun.IDNN: Intrusion detection algorithm based on nearest neighbor strategy[J].Computer Engineering and Applications,2010,46(26):72-75.
Authors:ZHANG Yan  TAO Jun
Affiliation:1.School of Computer Science and Technology, China University of Mining and Technology, Xuzhou, Jiangsu 221116, China 2.School of Computer Science and Engineering,Southeast University,Nanjing 210096,China)
Abstract:In the field of network intrusion detection,there are some problems such as high false alarm rate,requirement of high quality data for modeling the normal patterns and the deterioration of detection rate for network anomaly detection.This paper presents an intrusion detection algorithm based on nearest neighbor strategy in user transport behavior(IDNN),from the user's transmission behavior, it researches the IP address, port number, datagram type for user's datagram, and analyzes the demand for anomaly detection, the specific characteristics of audit data.The experiment demonstrates that the effect of IDNN algorithm is obvious for different users' applications services behavior in the intrusion detection.
Keywords:network security  anomaly detection  user's transmission behavior  Intrusion Detection algorithm based on Nearest Neighbor method(IDNN)
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号