首页 | 官方网站   微博 | 高级检索  
     

基于模糊概率赋值的新型贝叶斯异常检测模型
引用本文:金舒,刘凤玉.基于模糊概率赋值的新型贝叶斯异常检测模型[J].中国工程科学,2007,9(6):58-63.
作者姓名:金舒  刘凤玉
作者单位:南京理工大学计算机科学与技术系,南京,210094
摘    要:提出了一种结合模糊决策与贝叶斯方法的异常检测模型,该模型将系统中与安全相关的事件进行分类,并以模糊隶属度函数的形式给出各类事件发生异常的实时置信度。异常检测系统综合某时刻所有实时概率取值,做出贝叶斯决策。同简单使用阈值方法的贝叶斯入侵检测模型相比,采用了模糊概率赋值的贝叶斯异常检测模型,在提高对问题描述的精确性同时,由于它对多种类型安全相关事件提供支持而具有更好的适应性,可以更全面地对更复杂的系统行为进行建模。

关 键 词:入侵检测系统  异常检测  模糊概率赋值  贝叶斯置信网络
文章编号:1009-1742(2007)06-0058-06
修稿时间:2006-02-282006-05-09

A Novel Bayesian Anomaly Detection Model Using Fuzzy Probability Assignment
Jin Shu,Liu Fengyu.A Novel Bayesian Anomaly Detection Model Using Fuzzy Probability Assignment[J].Engineering Science,2007,9(6):58-63.
Authors:Jin Shu  Liu Fengyu
Abstract:To enhance the intrusion detection system with more accuracy and less false positive rate while still providing acceptable performance and adaptability, a Bayesian anomaly intrusion detection system using fuzzy probability assignment is presented in the paper. After categorizing the security related system events and properties into four models, which are represented by their corresponding fuzzy membership functions, the real- time probability of a specific security event will be calculated as according to the fuzzy membership function of the model it belongs to and a decision whether the supervised system is in a abnormal state is thus made from the synthesized probabilities of all these registered security events. Two separate algorithms, namely simple probability algorithm and Bayesian belief network algorithm, are provided in combining with the real-time fuzzy probabilities calculated. Simulations with a group of fine tuned coefficients prove the effectiveness of the two algorithms. Compared with previous work that employs the simple threshold methods in judging security related system events, the fuzzy approach suggested describes the probabilities of security events more accurately through utilizing the continuous fuzzy probability model and scales better as well for modeling various kinds of security related system properties in normal system behavior profiling.
Keywords:IDS  anomaly detection  fuzzy probability assignment  Bayesian belief network
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号