资源描述:
《基于ds证据理论的网络异常检测方法》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、ISSN1000-9825,CODENRUXUEWE-mail:jos@iscas.ac.cnJournalofSoftware,Vol.17,No.3,March2006,pp.463−471http://www.jos.org.cnDOI:10.1360/jos170463Tel/Fax:+86-10-62562563©2006byJournalofSoftware.Allrightsreserved.∗基于D-S证据理论的网络异常检测方法+诸葛建伟,王大为,陈昱,叶志远,邹维(北京大学计算机科学技术研究所,北京100871)ANetworkAnomalyDetectorBa
2、sedontheD-SEvidenceTheory+ZHUGEJian-Wei,WANGDa-Wei,CHENYu,YEZhi-Yuan,ZOUWei(InstituteofComputerScienceandTechnology,PekingUniversity,Beijing100871,China)+Correspondingauthor:Phn:+86-10-82529607,E-mail:zhugejianwei@icst.pku.edu.cn,http://www.icst.pku.edu.cnZhuGeJW,WangDW,ChenY,YeZY,ZouW.Anetwo
3、rkanomalydetectorbasedontheD-Sevidencetheory.JournalofSoftware,2006,17(3):463−471.http://www.jos.org.cn/1000-9825/17/463.htmAbstract:NetworkanomalydetectionhasbeenanactiveresearchtopicinthefieldofIntrusionDetectionformanyyears,however,ithasn’tbeenwidelyappliedinpracticeduetosomeissues.Theissu
4、esincludehighfalsealarmrate,limitedtypesofattackstheapproachcandetect,andthatsuchapproachcan’tperformreal-timeintrusiondetectioninhighspeednetworks.ThispaperpresentsanetworkanomalydetectorbasedonDempster-Shafer(D-S)evidencetheory.Thedetectorfusesmultiplefeaturesofnetworktraffictodecidewhether
5、thenetworkflowisnormal,andbysuchfusionitachieveslowfalsealarmrateandmissingrate.Italsoincorporatessomeself-adaptationmechanismstoyieldhighaccuracyofdetectionindynamicnetworks.Furthermore,light-computationfeaturesareusedtodevelopanefficientfusionmechanismtoguaranteehighperformanceofthealgorith
6、m.Onthe1999DARPA/LincolnLaboratoryintrusiondetectionevaluationdataset,thisdetectordetects69%attacksatlowfalsealarmrate.Suchresultisbetterthanthe50%detectionrateofEMERALD—thewinnerof1999DARPA/LincolnLaboratoryintrusiondetectionevaluation,andresultsfromotherresearchprojects.Keywords:intrusionde
7、tection;anomalydetection;D-Stheory;evidencetheory;datafusion摘要:网络异常检测技术是入侵检测领域研究的热点内容,但由于存在着误报率较高、检测攻击范围不够全面、检测效率不能满足高速网络实时检测需求等问题,并未在实际环境中得以大规模应用.基于D-S证据理论,提出了一种网络异常检测方法,能够融合多个特征对网络流量进行综合评判,有效地降低了误报率和漏报率,并引入自适应机制,以保证在实时动态变化的网络中的检测准确度.另外,选取计算