计算机工程与应用 ›› 2009, Vol. 45 ›› Issue (3): 205-206.DOI: 10.3778/j.issn.1002-8331.2009.03.061

• 工程与应用 • 上一篇    下一篇

频繁情节挖掘算法在伪装检测中的应用

于 枫1,高德远1,王 敏2   

  1. 1.西北工业大学 计算机学院,西安 710072
    2.空军工程大学 信息对抗系,西安 710068
  • 收稿日期:2008-09-22 修回日期:2008-12-01 出版日期:2009-01-21 发布日期:2009-01-21
  • 通讯作者: 于 枫

Applying frequent episode algorithm in masquerade detection

YU Feng1,GAO De-yuan1,WANG Min2   

  1. 1.School of Computer,Northwestern Polytechnical University,Xi’an 710072,China
    2.Department of Information Antagonism,Air Force Engineering University,Xi’an 710068,China
  • Received:2008-09-22 Revised:2008-12-01 Online:2009-01-21 Published:2009-01-21
  • Contact: YU Feng

摘要: 伪装攻击就是未授权用户通过伪装成合法用户来获得访问关键数据或更高层访问的权限。长久以来,检测伪装攻击在保障系统的网络安全中发挥着巨大的作用。首先讨论了一个用于评价伪装攻击检测算法有效性的方程,而后描述了频繁情节算法在检测伪装攻击中的应用,最后,采用SEA数据集对该算法进行了评估。结果证明频繁情节算法在检测伪装攻击时是行之有效的。

关键词: 频繁情节, 入侵检测, 伪装攻击检测

Abstract: Masquerade attacks are attempts by unauthorized users to gain access to critical data or higher access privileges,while pretending to be legitimate users.Detection of masquerade attacks is playing an important role in system security.This paper,discusses a formula to evaluate the effectiveness of masquerade detection algorithm and also presents an effective approach to masquerade detection by using frequent episode algorithm.It evaluates the method by performing experiments over UNIX command records from the SEA dataset.The result shows that the approach is quite effective in masquerade detection.

Key words: frequent episode, intrusion detection, masquerade detection