计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (34): 117-121.

• 网络、通信、安全 • 上一篇    下一篇

扩展D-S证据理论在网络异常检测中的研究

王 宏1,刘 渊2   

  1. 1.江南大学 物联网工程学院,江苏 无锡 214122
    2.江南大学 数字媒体学院,江苏 无锡 214122
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-12-01 发布日期:2011-12-01

Research on extended D-S theory in network anomaly detection

WANG Hong1,LIU Yuan2   

  1. 1.School of Internet of Things Engineering,Jiangnan University,Wuxi,Jiangsu 214122,China
    2.School of Digital Media,Jiangnan University,Wuxi,Jiangsu 214122,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-12-01 Published:2011-12-01

摘要: 网络异常检测是入侵检测系统中重要的组成部分,然而传统网络异常检测方法中存在虚警率高、单一检测算法对多种入侵行为的检测不够全面等问题。提出了一种基于改进D-S证据理论融合多个分类器的分布式网络异常检测模型及其融合方法。鉴于经典D-S证据理论在证据间存在冲突时的不合理,采用一种带权重的改进型D-S证据理论,提出一种全新的融合策略融合多个分类器建立异常检测模型。通过KDD99数据集对该模型进行验证,结果证明该异常检测模型可以明显降低网络异常检测的虚警率,提高检测精度。

关键词: D-S证据理论, 异常检测, 数据融合

Abstract: Network anomaly detection is an important part of the intrusion detection system,however,there are many problems in traditional network anomaly detection methods,such as high false positive rate and the limitation of detecting multiple types of the intrusion actions.A distributed anomaly detection model and the fusion method are proposed based on extended D-S evidence theory.Meanwhile,considering the unreasonableness in the traditional D-S evidence theory when there exist conflictions in the evidences,an extended D-S evidence theory with weights is adopted,and a newly fusion policy is proposed to build an anomaly detection model with multiple classifiers.According to the verification of the KDD99 data set,experiments show that the proposed model and method can obviously reduce the false positve rate,and simultaneously improve the detection rate.

Key words: D-S evidence theory, anomaly detection, data fusion