计算机工程与应用 ›› 2010, Vol. 46 ›› Issue (26): 72-75.DOI: 10.3778/j.issn.1002-8331.2010.26.023

• 网络、通信、安全 • 上一篇    下一篇

基于最近邻策略的入侵检测方法研究

张 艳1,陶 军2   

  1. 1.中国矿业大学 计算机科学与技术学院,江苏 徐州 221116
    2.东南大学 计算机科学与工程学院,南京 210096
  • 收稿日期:2010-05-20 修回日期:2010-07-06 出版日期:2010-09-11 发布日期:2010-09-11
  • 通讯作者: 张 艳

IDNN:Intrusion detection algorithm based on nearest neighbor strategy

ZHANG Yan1,TAO Jun2   

  1. 1.School of Computer Science and Technology,China University of Mining and Technology,Xuzhou,Jiangsu 221116,China
    2.School of Computer Science and Engineering,Southeast University,Nanjing 210096,China
  • Received:2010-05-20 Revised:2010-07-06 Online:2010-09-11 Published:2010-09-11
  • Contact: ZHANG Yan

摘要: 针对目前网络入侵检测系统中,大多数网络异常检测技术仍存在误报率较高、对建立检测模型的数据要求过高、检测率不高等问题。从用户的传输行为出发,研究体现用户行为的数据报文中的IP地址、端口号、报文类型、报文长度,对异常检测的需求、审计数据的具体特征进行分析,提出了一种基于最近邻策略的用户传输行为入侵检测算法-IDNN算法。通过仿真实验,表明IDNN算法在针对不同用户应用服务行为的入侵检测中效果明显。

关键词: 网络安全, 异常检测, 用户传输行为, IDNN算法

Abstract: In the field of network intrusion detection,there are some problems such as high false alarm rate,requirement of high quality data for modeling the normal patterns and the deterioration of detection rate for network anomaly detection.This paper presents an intrusion detection algorithm based on nearest neighbor strategy in user transport behavior(IDNN),from the user’s transmission behavior,it researches the IP address,port number,datagram type for user’s datagram,and analyzes the demand for anomaly detection,the specific characteristics of audit data.The experiment demonstrates that the effect of IDNN algorithm is obvious for different users’ applications services behavior in the intrusion detection.

Key words: network security, anomaly detection, user’s transmission behavior, Intrusion Detection algorithm based on Nearest Neighbor method(IDNN)

中图分类号: