首页> 外文OA文献 >A two-stage flow-based intrusion detection model for next-generation networks
【2h】

A two-stage flow-based intrusion detection model for next-generation networks

机译:下一代网络的两级流动入侵检测模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The next-generation network provides state-of-the-art access-independent services over converged mobile and fixed networks. Security in the converged network environment is a major challenge. Traditional packet and protocol-based intrusion detection techniques cannot be used in next-generation networks due to slow throughput, low accuracy and their inability to inspect encrypted payload. An alternative solution for protection of next-generation networks is to use network flow records for detection of malicious activity in the network traffic. The network flow records are independent of access networks and user applications. In this paper, we propose a two-stage flow-based intrusion detection system for next-generation networks. The first stage uses an enhanced unsupervised one-class support vector machine which separates malicious flows from normal network traffic. The second stage uses a self-organizing map which automatically groups malicious flows into different alert clusters. We validated the proposed approach on two flow-based datasets and obtained promising results.
机译:下一代网络提供了通过融合移动和固定网络的最先进的访问无关服务。融合网络环境中的安全是一项重大挑战。由于慢吞吐量,低精度及其无法检查加密的有效载荷,传统的数据包和基于协议的入侵检测技术不能用于下一代网络。保护下一代网络的替代解决方案是使用网络流记录来检测网络流量中的恶意活动。网络流记录与接入网络和用户应用程序无关。在本文中,我们提出了一种用于下一代网络的两级流动入侵检测系统。第一阶段使用增强的无监督一类支持向量机,将恶意流从正常的网络流量分开。第二阶段使用自组织地图,它自动将恶意流入不同的警报群集。我们在两个基于流基的数据集中验证了所提出的方法,并获得了有希望的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号