计算机工程与应用 ›› 2013, Vol. 49 ›› Issue (7): 81-84.

• 网络、通信、安全 • 上一篇    下一篇

基于改进属性加权的朴素贝叶斯入侵取证研究

贾  娴1,2,刘培玉1,2,公  伟1,2   

  1. 1.山东师范大学 信息科学与工程学院,济南 250014
    2.山东省分布式计算机软件新技术重点实验室,济南 250014
  • 出版日期:2013-04-01 发布日期:2013-04-15

Research of intrusion forensics based on improved attribute Weighted Naive Bayes

JIA Xian1,2, LIU Peiyu1,2, GONG Wei1,2   

  1. 1.School of Information Science and Engineering, Shandong Normal University, Ji’nan 250014, China
    2.Shandong Provincial Key Laboratory for Distributed Computer Software Novel Technology, Ji’nan 250014, China
  • Online:2013-04-01 Published:2013-04-15

摘要: 针对传统朴素贝叶斯分类模型在入侵取证中存在的特征项冗余问题,以及没有考虑入侵行为所涉及的数据属性间的差别问题,提出一种基于改进的属性加权朴素贝叶斯分类方法。用一种改进的基于特征冗余度的信息增益算法对特征项集进行优化,并在此优化结果的基础上,提取出其中的特征冗余度判别函数作为权值引入贝叶斯分类算法中,对不同的条件属性赋予不同的权值。经实验验证,该算法能有效地选择特征向量,降低分类干扰,提高检测精度。

关键词: 入侵取证, 朴素贝叶斯, 加权朴素贝叶斯, 信息增益, 特征冗余度, 属性加权

Abstract: Traditional Naive Bayes classification exists the issues of feature redundancy in intrusion forensics and neglects the difference between data attributes in different intrusion actions. For these issues, an improved Weighted Naive Bayes classification method by setting attribute weights is proposed. A new Information Gain algorithm based on feature redundancy is used to optimize the set of feature, then the discriminant of feature redundancy extracted as weights is introduced to Bayes classification algorithm based on this optimization results. The different condition attributes are weighted differently. The experimental results show that the new algorithm can effectively select features, reduce classification interference and improve detection accuracy.

Key words: intrusion forensics, Naive Bayes, Weighted Naive Baye, Information Gain, feature redundancy, attribute weighted