首页> 美国政府科技报告 >On-line Adaptive IDS Scheme for Detecting Unknown Network Attacks Using HMM Models
【24h】

On-line Adaptive IDS Scheme for Detecting Unknown Network Attacks Using HMM Models

机译:基于Hmm模型检测未知网络攻击的在线自适应IDs方案

获取原文

摘要

An important problem in designing IDS schemes is an optimal trade- off between good detection and false alarm rate. Specifically, in order to detect unknown network attacks, existing IDS schemes use anomaly detection which introduces a high false alarm rate. In this thesis we propose an IDS scheme based on overall behavior of the network. We capture the behavior with probabilistic models (HMM) and use only limited logic information about attacks. Once we set the detection rate to be high, we filter out false positives through stages. The key idea is to use probabilistic models so that even an unknown attack can be detected, as well as a variation of a previously known attack. The scheme is adaptive and real-time Simulation study showed that we can have a perfect detection of both known and unknown attacks while maintaining a very low false alarm rate.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号