...
首页> 外文期刊>International Journal of Applied Mathematics & Statistics >A connections-constrained model for intrusion detection in Ad-Hoc networks
【24h】

A connections-constrained model for intrusion detection in Ad-Hoc networks

机译:Ad-Hoc网络中用于入侵检测的连接受限模型

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this paper we proposed a novel adaptive model for developing and implementing intrusion detection systems. The adaptive model is consisted by two parts, each one of which is based on statistical properties of the packets connections. By define the Entropy of joint Packets and Connections, we propose the two-steps of Connections-constrained Detection Mode to perform attacks detection. At a particular connection, the Packets Communication Monitoring (PCM) module observes packets IP address and collects statistics of Packets and Bytes of connections. The second component is Malicious Behavior Analyse (MBA) module, which analyse the traffic behaviour. Experiment results performed using the DARPA dataset and KDD, which indicate that the proposed approach can significantly reduce the percentage of false positives. The adaptive mode based on Entropy of joint Packets and Connections is a significant advantage in detection speed and performance.
机译:在本文中,我们提出了一种用于开发和实施入侵检测系统的新型自适应模型。自适应模型由两部分组成,每一部分都基于数据包连接的统计属性。通过定义联合包和连接的熵,我们提出了两步连接约束检测模式来进行攻击检测。在特定连接上,数据包通信监视(PCM)模块观察数据包的IP地址,并收集数据包和连接字节数的统计信息。第二个组件是恶意行为分析​​(MBA)模块,该模块分析流量行为。使用DARPA数据集和KDD进行的实验结果表明,该方法可以显着减少误报的百分比。基于联合数据包和连接的熵的自适应模式在检测速度和性能方面具有显着优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号