首页> 外文会议>2010 2nd International Conference on e-Business and Information System Security (EBISS2010) >Research and Design for Intrusion Detection System with Hybrid Detector and Apriori Algorithm
【24h】

Research and Design for Intrusion Detection System with Hybrid Detector and Apriori Algorithm

机译:混合检测器和Apriori算法的入侵检测系统的研究与设计

获取原文
获取原文并翻译 | 示例

摘要

Network and host Intrusion Detection Systems (IDS) have become a standard component in security infrastructures. As the action of intrusion represents variable, complicated, and uncertainty characteristic, they face so many problems to resolve for intrusion detection. Each approach has its strengths and weaknesses. We propose a hybrid IDS, which combines network and host IDS, with anomaly and misuse detection mode, utilizes auditing programs to extract an extensive set of features that describe each network connection or host session, and applies data mining programs to learn rules that accurately capture the behavior of intrusions and normal activities. We use an association rule to track all relevant data dependency rule sets for different access roles using a hierarchical structure. We identify malicious transactions from the transaction logs in the database using the data dependency rule sets. These rule sets are continuously updated and stored in a repository. The optimized algorithm actually improves the performance of IDS. Our approach is shown to reduce data access bottlenecks, and ensures minimal manual intervention for maintaining a secure database.
机译:网络和主机入侵检测系统(IDS)已成为安全基础结构中的标准组件。由于入侵行为表现出可变,复杂和不确定的特征,因此它们面临着许多问题需要解决以进行入侵检测。每种方法都有其优点和缺点。我们提出了一种混合IDS,它将网络和主机IDS与异常和滥用检测模式结合在一起,利用审核程序来提取描述每个网络连接或主机会话的广泛功能集,并应用数据挖掘程序来学习可准确捕获的规则入侵行为和正常活动。我们使用关联规则来使用分层结构跟踪不同访问角色的所有相关数据依赖关系规则集。我们使用数据依赖规则集从数据库中的交易日志中识别恶意交易。这些规则集会不断更新并存储在存储库中。经过优化的算法实际上提高了IDS的性能。已证明我们的方法可以减少数据访问瓶颈,并确保维护安全数据库的手动干预最少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号