首页 | 官方网站   微博 | 高级检索  
     

网络入侵检测的GEP规则提取算法研究
引用本文:唐莞,曹阳,杨喜敏,覃俊.网络入侵检测的GEP规则提取算法研究[J].计算机科学,2009,36(11):79-82.
作者姓名:唐莞  曹阳  杨喜敏  覃俊
作者单位:1. 武汉大学电子信息学院软件工程国家重点实验室,武汉,430070;中南民族大学计算机科学学院,武汉,430074
2. 武汉大学电子信息学院软件工程国家重点实验室,武汉,430070
3. 中南民族大学计算机科学学院,武汉,430074;华中科技大学计算机科学与技术学院,武汉,430074
4. 华中科技大学计算机科学与技术学院,武汉,430074
基金项目:国家重点基础研究发展计划,国家自然科学基金,湖北省自然科学基金 
摘    要:针对基于机器学习网络入侵检测存在的未知攻击检测率低、规则多而复杂导致检测效率不高等问题,提出了基于约束的基因表达式编程(GEP)规则提取算法(CGREA).用GEP模式表示入侵检测规则,定义了约束文法对规则个体进行约束,以满足规则的充分性和封闭性.CGREA算法限定GEP规则基因头部各类符号的随机选择数目比例.并采用精英策略以保证算法收敛性.用KDDCUP'99数据集对CGREA算法提取的入侵检测规则进行评估,总攻击检测率为91.36%,其中有3种未知攻击的检测率超过88%.结果表明,CGREA算法能在较小种群和有限代数内提取出简单而有效的规则,未知攻击检测率和检测性能也得到提高.

关 键 词:网络入侵检测  基因表达式编程  规则提取  约束文法  精英策略
收稿时间:2008/12/9 0:00:00
修稿时间:3/9/2009 12:00:00 AM

Study on GEP Rule Extraction Algorithm for Network Intrusion Detection
TANG Wan,CAO Yang,YANG Xi-min,QIN Jun.Study on GEP Rule Extraction Algorithm for Network Intrusion Detection[J].Computer Science,2009,36(11):79-82.
Authors:TANG Wan  CAO Yang  YANG Xi-min  QIN Jun
Affiliation:(State Key Laboratory of Software Engineering, School of Electronic Information, Wuhan University, Wuhan 430070, China);(College of Computer Science,South-Central University for Nationalities, Wuhan 430074,China);(College of Computer Science &Technology, Huazhong University of Science &Technology, Wuhan 430074, China)
Abstract:Network intrusion detection based on machine learning suffers from the problems of low detection ratio for unknown intrusion and low detection efficiency due to many complex rules. To solve these problems, a constraint based gene expression programming (GEP) rule extraction algorithm (CGREA) was proposed. The intrusion detection rules were represented based on GEP model,and a constraint grammar was defined to guarantee the rules closeness and adequacy. It restricted the ratio of randomly selecting various symbols in the gene head of GEP rules, and used the elitist strategy to guarantee convergence. The KDI)CUP' 99 DATA Set was used for evaluation the intrusion detection rules auto-extracted by CGREA. A 91%probability of detection was achieved, and three unknown attacks' probabilities of detection were more than 88 %. These results indicate that the intrusion detection rules that extracted by CGREA are effective, simple, and capable of detecting unknown intrusions. Moreover, the efficiency of rule generation and detection is improved.
Keywords:Network intrusion detection  GEP (gene expression programming)  Rule extraction  Constraint grammar  E-litist strategy
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机科学》浏览原始摘要信息
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号