首页 | 本学科首页   官方微博 | 高级检索  
     检索      

特定应用环境下的入侵检测架构
引用本文:王怀彬,刘凯,王鹏涛.特定应用环境下的入侵检测架构[J].天津大学学报(自然科学与工程技术版),2006,39(Z1):375-378.
作者姓名:王怀彬  刘凯  王鹏涛
作者单位:天津理工大学计算机系 天津300191(王怀彬,王鹏涛),北京信息工程学院计算机信息系统系 北京100101(刘凯)
基金项目:国家自然科学基金(66272011).
摘    要:异常检测可以认为是通过对用户正常行为及系统正常应用环境的学习来识别异常的过程.由于系统及应用环境的复杂性,异常检测还难以达到很高的识别精度.为此,针对在物理上与Internet网完全隔离的计算机网络应用环境,亦即内网,提出基于mobile agent(MA)的多层次入侵检测架构,利用自组织映射网络方法,在不同层次的agent中建立二堆网格的自组织映射网络模型,分别检测目标系统不同层次上的异常现象.实验结果表明,在入侵者攻击的持续时间内,本系统通过多次采样的办法可以使检测率提高到满意的程度.

关 键 词:入侵检测  自组织映射  移动代理  网络安全
文章编号:0493-2137(2006)增刊-0375-04
修稿时间:2005年10月22

Intrusion Detection Architecture Under Specific Application Environment
WANG Huai-bin LIU Kai WANG Peng-tao.Intrusion Detection Architecture Under Specific Application Environment[J].Journal of Tianjin University(Science and Technology),2006,39(Z1):375-378.
Authors:WANG Huai-bin LIU Kai WANG Peng-tao
Institution:WANG Huai-bin~1 LIU Kai~2 WANG Peng-tao~1 1.Department of Computer,Tianjin University of Technology,Tianjin 300191,China, 2.Department of Computer Information System,Beijing Information Technology Institute,Beijing 100101,China
Abstract:Abnormal detection is considered as a process of recognizing the anomaly by learning to characterize the norm behaviors of user and system application environment.Because of complexity of application on net- work,it is difficult to improve the precision of abnormal detection.A multiple-layer architecture based on mo- bile agent(MA) for intrusion detection is presented in the computer network environment isolated with the Inter- net,which is often called isolated network.It utilizes the methodology of self-organizing map(SOM)neural network to build the two-dimension grid model of SOM neural network and detect the anomaly of the object sys- tem on different layers.The experiment shows that this multiple-layer architecture can improve the rate of intru- sion detection by sampling time after time in the duration of the network attacked.
Keywords:intrusion detection  self-organizing map  mobile agent  network security
本文献已被 CNKI 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号