首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于条件随机场的实时入侵检测系统框架实现
引用本文:顾佼佼,姜文志,栗飞,胡文萱.基于条件随机场的实时入侵检测系统框架实现[J].海军航空工程学院学报,2011,26(5):543-548.
作者姓名:顾佼佼  姜文志  栗飞  胡文萱
作者单位:1. 海军航空工程学院兵器科学与技术系,山东烟台,264001
2. 海军航空工程学院指挥系,山东烟台,264001
3. 海军航空工程学院外训系,山东烟台,264001
摘    要:入侵检测系统(IDS)如今是网络的重要组成部分,现在各种无线网络及专用网络都已配备检测系统。随着网络技术的迅猛发展,入侵检测的技术已经从简单的签名匹配发展成能充分利用上下文信息的基于异常和混合的检测方式。为了从网络环境大量记录信息中正确有效地识别出入侵,提出一种基于层叠条件随机场模型的入侵检测框架,该框架针对4类不同攻...

关 键 词:入侵检测  条件随机场  机器学习  层叠模型

Real-Time Intrusion Detection System FrameworkBased on Conditional Random Fields
GU Jiao-jiao,JIANG Wen-zhi,LI Feib and HU Wen-xuanc.Real-Time Intrusion Detection System FrameworkBased on Conditional Random Fields[J].Journal of Naval Aeronautical Engineering Institute,2011,26(5):543-548.
Authors:GU Jiao-jiao  JIANG Wen-zhi  LI Feib and HU Wen-xuanc
Institution:GU Jiao-jiaoa,JIANG Wen-zhia,LI Feib,HU Wen-xuanc(Naval Aeronautical and Astronautical University a.Department of Ordnance Science and Technology,b.Department of Command,c.Department of Foreign Training,Yantai Shandong 264001,China)
Abstract:Intrusion detection systems are now an essential component in the all kinds of network even including wireless ad hoc network. With the rapid advancement in the network technologies, the focus of intrusion detection has shifted from simple signature matching approaches to detecting attacks based on analyzing contextual information that employed in based on anomaly and hybrid intrusion detection approaches In order to correctly and effectively recognizing the hidden attack intrusion from large volume of low level system logs, a layered based on anomaly intrusion detection framework was proposed using conditional random fields to detect a wide variety of attacks. For models separately, and then processes the data layer fou by r classes of attack the framework trains four different layer to detect intrusion. Attacks could be identified and intrusion response could be initiated in real time with this framework and the system adaptability and portability were improved significantly reduce the system false alarm rate and false detection rate. Experiments show that the CRF model could detect attacks effectively
Keywords:intrusion detection  CRFs  Machine Learning  overlay model
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《海军航空工程学院学报》浏览原始摘要信息
点击此处可从《海军航空工程学院学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号