欢迎来到天天文库
浏览记录
ID:36537409
大小:1.82 MB
页数:53页
时间:2019-05-11
《分布式入侵检测系统中的报警融合》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、北京交通大学硕士学位论文分布式入侵检测系统中的报警融合姓名:何肖慧申请学位级别:硕士专业:计算机应用技术指导教师:田盛丰20061201北京交通大学硕士学位论文ABSTRACTWiththedevelopmentofIntemet,computernetworksecurityisbecomingmoreandmoreconcernedquestion.Toenhancethesecuritycapabilityofcomputernetwork,peoplehaveadoptedmanysecuritytechnol
2、ogiesincludingencryption,identityrecognition,andageesscontr01.Withthedevelopmentofintrusiondetectiontechnology,IDS(IntrusionDetectionSystem)hasbecomeallimportantmethodinnetworksecuritysystem.Inthepracticalenvironment,IDSalwaysproducesalotoffalsepositives,falsene
3、gativealertsandduplicatealerts,whichcallnotenableadministratortodistinguishthealertseffectively,therebyreducingtheeffectivenessofIDS.Therefore,itisnecessarytoadoptanefficientmethodtodeleteredundantalerts,reducefalsepositiveratioandfalsenegativeratioinordertorais
4、etheefficiencyofIDS.Inthispaper,Wedeeplyanalyzethearchitecture,datasourceanddetectiontechnologyofthepresemIDS.Wetakearesearchonthealertmanagementinthedistributedintrusiondetectionenvironment,andthemaincontentisasfollows:1)Introducingadistribmedintrusiondetection
5、system,anddescribingitsarchitectureandfunctionalitycompletely.2)Emphasizingontheresearchofalertfusiontechnology,designingandimplementingthemoduleofalertfusion,whichconsistsoftwosub-modules:alertaggregationandalertcorrelation.3)Theadaptivealertaggregationalgorith
6、mcalleffectivelyaggregateduplicatealertsandreducenetworktrafficcausedbythem.4)ThealertcorrelationalgorithmbasedonfuzzycomprehensiveevaluationCannotonlycorrelatethealertsfromdifferentIDS,butalsothealertsfromdifferentstagesoftheinvasion,whichisl℃presentedbyanalert
7、threadinthemodel.Thealgorithmcanreducethefalsepositivealertsandfalsenegativealerts,andalso,themodelcouldprovidesomecompoundparametersforfurtheronlineriskassessmentandintrusionresponsedecision.5)Introducingtheconceptandroleofalertconfidencelearningandalertverific
8、ationalgorithm.Thispaperfirstintroducesthemodelstructure,generalfeaturesanddifferentclassificationofIDS,thendescribesthedistributedintrusiondetectionsystemalerts北京交通大
此文档下载收益归作者所有