首页 | 官方网站   微博 | 高级检索  
     

基于模糊粗糙集属性约简与GMM-LDA最优聚类簇特征学习的自适应网络入侵检测
引用本文:刘金平,张五霞,唐朝晖,何捷舟,徐鹏飞.基于模糊粗糙集属性约简与GMM-LDA最优聚类簇特征学习的自适应网络入侵检测[J].控制与决策,2019,34(2):243-251.
作者姓名:刘金平  张五霞  唐朝晖  何捷舟  徐鹏飞
作者单位:湖南师范大学信息科学与工程学院,长沙410081;湖南师范大学计算与随机数学教育部重点实验室,长沙410081,湖南师范大学信息科学与工程学院,长沙410081,中南大学信息科学与工程学院,长沙410083,湖南师范大学信息科学与工程学院,长沙410081,湖南师范大学信息科学与工程学院,长沙410081
基金项目:国家自然科学基金项目(61501183, U1701261, 61771492);湖南省自然科学基金项目(2018JJ3349);图像信息处理与智能控制教育部重点实验室(华中科技大学)开放基金项目(IPIC2017-03).
摘    要:网络入侵方式已日趋多样化,其隐蔽性强且变异性快,开发灵活度高、适应性强的实时网络安全监测系统面临严峻挑战.对此,提出一种基于模糊粗糙集属性约简(FRS-AR)和GMM-LDA最优聚类簇特征学习(GMM-LDA-OCFL)的自适应网络入侵检测(ANID)方法.首先,引入一种基于模糊粗糙集(FRS)信息增益率的属性约简(AR)方法以实现网络连接数据最优属性集选择;然后,提出一种基于GMM-LDA的最优聚类簇特征学习方法,以获得正常模式特征库和入侵模式库的最优特征表示,同时引入模式库自适应更新机制,使入侵检测模型能够适应网络环境动态变化.KDD99数据集和基于Nidsbench的网络虚拟仿真实验平台的入侵检测结果表明,所提出的ANID方法能有效适应网络环境动态变化,可实时检测出真实网络连接数据中的各种入侵行为,其性能优于当前常用的入侵检测方法,应用前景广阔.

关 键 词:入侵检测  高斯混合模型聚类  模式匹配  模糊粗糙集  信息增益  模式更新

Adaptive network intrusion detection based on fuzzy rough set-based attribute reduction and GMM-LDA-based optimal cluster feature learning
LIU Jin-ping,ZHANG Wu-xi,TANG Zhao-hui,HE Jie-zhou and XU Peng-fei.Adaptive network intrusion detection based on fuzzy rough set-based attribute reduction and GMM-LDA-based optimal cluster feature learning[J].Control and Decision,2019,34(2):243-251.
Authors:LIU Jin-ping  ZHANG Wu-xi  TANG Zhao-hui  HE Jie-zhou and XU Peng-fei
Affiliation:College of Information Science and Engineering,Hu''nan Normal University,Changsha 410081,China;Key Laboratory of Computing and Stochastic Mathematics,Ministry of Education,Hu''nan Normal University,Changsha 410081,China,College of Information Science and Engineering,Hu''nan Normal University,Changsha 410081,China,School of Information Science and Engineering,Central South University,Changsha 410083,China,College of Information Science and Engineering,Hu''nan Normal University,Changsha 410081,China and College of Information Science and Engineering,Hu''nan Normal University,Changsha 410081,China
Abstract:With the increasing diversity and rapid variability of network intrusion, the development of real-time network security monitoring systems with high flexibility and strong adaptability still faces severe challenges. Therefore adaptive network intrusion detection(ANID) method based on fuzzy rough set attribute reduction(FRS-AR) and Gaussian mixture model linear discriminant aualysis(GMM-LDA) optimal cluster feature learning(GMM-LDA-OCFL) is proposed. Based on the fuzzy rough set theory, the optimal attribute set of network connection data is selected automatically by information gain rate measurement. Then, an optimal cluster feature learning method based on GMM-LDA is proposed to obtain the optimal feature representation of the normal mode feature library and the intrusion mode feature library. At the same time, the adaptive on-line update mechanism of the normal(abnormal) pattern feature library is introduced, so that the detection model can adapt itself to dynamic network changes. The test results of KDD99 and network simulation experiment platform based on Nidsbench show that the proposed method can effectively adapt to the dynamic changes of the network environment and various intrusion behaviors in the real network connection data can be detected in real time. And the performance of the proposed method is better than that of the existing commonly-used intrusion detection methods, which has potentially wide application prospects.
Keywords:
点击此处可从《控制与决策》浏览原始摘要信息
点击此处可从《控制与决策》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号