计算机工程与应用 ›› 2007, Vol. 43 ›› Issue (22): 122-125.

• 网络、通信与安全 • 上一篇    下一篇

基于多维二进制搜索树的异常检测技术

仇明华,殷丽华,李 斌   

  1. 哈尔滨工业大学 计算机网络与信息安全技术中心,哈尔滨 150001
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-01 发布日期:2007-08-01
  • 通讯作者: 仇明华

Anomaly detection technology based on multidimensional binary search tree

QIU Ming-hua,YIN Li-hua,LI Bin   

  1. Computer Network and Information Security Technology Center,Harbin Institute of Technology,Harbin 150001,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-01 Published:2007-08-01
  • Contact: QIU Ming-hua

摘要: 将多维二进制搜索树(kd树)应用于异常检测,用kd树对网络数据进行组织、建立用户轮廓并以此为基础实现了一个异常检测系统,通过实验给出了系统对不同种类攻击的检测效果。实验结果表明,kd树在异常检测中具有很高的适用性。

关键词: 异常检测, kd树, 用户轮廓

Abstract: This paper applies multidimensional binary search tree(kd tree) to anomaly detection,implements an anomaly detection system based on the user profile erected by kd tree,and finally,by achieving the results of the system in the light of divert types of attacks,this paper manifests the the high feasibility of applying kd-tree into anomaly detection.

Key words: anomaly detection, kd tree, user profile