基于条件随机场的实时入侵检测系统框架实现
DOI:
作者:
作者单位:

(1.海军航空工程学院兵器科学与技术系,山东 烟台 264001; 2.海军航空工程学院指挥系,山东 烟台 264001; 3.海军航空工程学院外训系,山东 烟台 264001)

作者简介:

通讯作者:

中图分类号:

TP393.081

基金项目:


Real-Time Intrusion Detection System FrameworkBased on Conditional Random Fields
Author:
Affiliation:

(1. Naval Aeronautical and Astronautical UniversityDepartment of Ordnance Science and Technology,Yantai Shandong 264001,China ;2. Naval Aeronautical and Astronautical UniversityDepartment of Command,Yantai Shandong 264001,China; 3. Naval Aeronautical and Astronautical UniversityDepartment of Foreign Training,Yantai Shandong 264001,China)

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    入侵检测系统(IDS)如今是网络的重要组成部分,现在各种无线网络及专用网络都已配备检测系统。随着网络技术的迅猛发展,入侵检测的技术已经从简单的签名匹配发展成能充分利用上下文信息的基于异常和混合的检测方式。为了从网络环境大量记录信息中正确有效地识别出入侵,提出一种基于层叠条件随机场模型的入侵检测框架,该框架针对4类不同攻击方式利用条件随机场模型分别进行识别训练,然后逐层进行入侵识别,提高了入侵检测系统的自适应性和可移植性,降低了系统的误报率和误检率,可高精度的识别各种攻击。实验结果表明,该框架可实时有效的识别攻击,启动响应机制进行处理。

    Abstract:

    Intrusion detection systems are now an essential component in the all kinds of network even including wireless ad hoc network. With the rapid advancement in the network technologies, the focus of intrusion detection has shifted from simple signature matching approaches to detecting attacks based on analyzing contextual information that employed in based on anomaly and hybrid intrusion detection approaches. In order to correctly and effectively recognizing the hidden attack intrusion from large volume of low level system logs, a layered based on anomaly intrusion detection framework was proposed using conditional random fields to detect a wide variety of attacks. For four classes of attack the framework trains four different models separately, and then processes the data layer by layer to detect intrusion. Attacks could be identified and intrusion response could be initiated in real time with this framework and the system adaptability and portability were improved significantly reduce the system false alarm rate and false detection rate. Experiments show that the CRF model could detect attacks effectively.

    参考文献
    相似文献
    引证文献
引用本文

顾佼佼,姜文志,栗飞,胡文萱.基于条件随机场的实时入侵检测系统框架实现[J].海军航空大学学报,2011,26(5):543-548
GU Jiao-jiaoa, JIANG Wen-zhia, LI Feib, HU Wen-xuanc. Real-Time Intrusion Detection System FrameworkBased on Conditional Random Fields[J]. JOURNAL OF NAVAL AVIATION UNIVERSITY,2011,26(5):543-548

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2018-07-05
  • 出版日期: