首页> 外文学位 >An agent-based intrusion detection system using fuzzy logic for computer system threat evaluation.
【24h】

An agent-based intrusion detection system using fuzzy logic for computer system threat evaluation.

机译:使用模糊逻辑的基于代理的入侵检测系统,用于计算机系统威胁评估。

获取原文
获取原文并翻译 | 示例

摘要

This dissertation proposes a new approach for threat evaluation in distributed computing systems. Although anomaly-based intrusion detection systems are very helpful in detecting unknown attacks that are not defined in the signature and rule-based analysis of the misuse detection approach, there are many difficulties in accurately and efficiently performing anomaly detections. Tuning statistical anomaly detection engines is a significant challenge that often causes high false alarm rates. Also, many types of intrusions cannot be crisply defined and the degree of alert (threat level) that can occur with intrusions is often imprecisely defined.; This dissertation explores the use of fuzzy logic as the threat evaluation engine for anomaly-based intrusion detection system. It presents a novel agent-based anomaly intrusion detection architecture using fuzzy logic to overcome the anomaly intrusion detection systems drawbacks and to present an accurate threat evaluation detection engine. The new architecture was experimentally implemented, and compared to existing intrusion detection systems. An experiment was developed to simulate a difficult network intrusion called “Doorknob Rattling.” Two other experiments were developed to evaluate the adaptability and the robustness of the proposed agent-based anomaly intrusion detection system respectively. In addition, two experiments were developed to evaluate the effectiveness of the fuzzy agent-based intrusion detection system and to create a flexible detection system that tolerates legitimate variations in user behavior.
机译:本文提出了一种新的分布式计算系统威胁评估方法。尽管基于异常的入侵检测系统在检测未知攻击方面非常有帮助,而这些未知攻击在签名和基于规则的滥用检测方法分析中未定义,但在准确有效地执行异常检测方面仍有许多困难。调整统计异常检测引擎是一项重大挑战,通常会导致较高的误报率。同样,许多类型的入侵无法被明确定义,并且入侵可能发生的警报程度(威胁级别)通常不准确。本文探讨了模糊逻辑作为基于异常的入侵检测系统的威胁评估引擎的应用。它提出了一种新颖的基于代理的使用模糊逻辑的异常入侵检测体系结构,以克服异常入侵检测系统的缺陷,并提出一种准确的威胁评估检测引擎。新的体系结构已通过实验实现,并与现有的入侵检测系统进行了比较。开发了一个实验来模拟困难的网络入侵,称为“ Doorknob Rattling”。开发了另外两个实验来分别评估所提出的基于代理的异常入侵检测系统的适应性和鲁棒性。此外,还开发了两个实验,以评估基于模糊代理的入侵检测系统的有效性,并创建可容忍用户行为的合法变化的灵活检测系统。

著录项

  • 作者

    Hamed, Essam M.;

  • 作者单位

    University of Louisville.;

  • 授予单位 University of Louisville.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2001
  • 页码 144 p.
  • 总页数 144
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:47:08

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号