计算机工程与应用 ›› 2008, Vol. 44 ›› Issue (12): 101-102.

• 网络、通信、安全 • 上一篇    下一篇

一种新的基于平均隶属度的网络入侵检测方法

冯乃勤,郭战杰,南书坡,董亚杰   

  1. 河南师范大学 计算机与信息技术学院,河南 新乡 453007
  • 收稿日期:2007-12-03 修回日期:2008-02-27 出版日期:2008-04-21 发布日期:2008-04-21
  • 通讯作者: 冯乃勤

New network intrusion detection method based on average membership

FENG Nai-qin,GUO Zhan-jie,NAN Shu-po,DONG Ya-jie   

  1. College of Computer &Information Technology,Henan Normal University,Xinxiang,Henan 453007,China
  • Received:2007-12-03 Revised:2008-02-27 Online:2008-04-21 Published:2008-04-21
  • Contact: FENG Nai-qin

摘要: 针对传统入侵检测算法存在的不足,提出了一种新的基于平均隶属度的网路入侵检测方法——AMID,并且给出了相应的算法。这种方法通过度量实时行为和正常行为的贴近程度来判断当前是否存在异常行为,理论基础夯实,判断过程简单易于实现。实验结果说明,该方法在降低系统误报率方面有较为明显的改进。

关键词: 入侵检测, 隶属度, 子集度, 系统调用

Abstract: Aiming at the shortages of traditional intrusion method,this paper presents a new Network Intrusion Detection Method-AMID,and its algorithm.By measuring the close degree between real time behavior and normal behavior,the proposed method judges if there are intrusions.The experiment shows that this method has considerable improvement in decreasing the false positive rate。

Key words: intrusion detection, membership degree, subset degree, system call