期刊文献+

基于入侵事件预测的网络安全预警方法 被引量:11

Intrusion Event Based Early Warning Method for Network Security
在线阅读 下载PDF
导出
摘要 提出了一种基于入侵事件统计规律的安全预警方法,包括聚类分析、周期分析、趋势预测。依据某一攻击发生的历史分布特点,通过聚类分析,取得入侵频数序列;周期分析确定入侵事件发生的周期性;预测未来时间入侵发生趋势。讨论了时间粒度对预测效果的影响,以及算法对周期性攻击预测的适应性。实验结果表明:该方法对周期性攻击的预警误报率为19%和漏报率为27%。 Statistics based early warning method is proposed. It covers clustering, cycle analyzis and prediction. Clustering results in intrusion frequency according historical intrusion events. Cycle analysis testifies whether there is a cycle. Prediction gives future frequency of attacks. Relationship between clustering time and false positive rate and false negative rate is discussed and experimented. It shows periodical intrusion events gains better result than the non-periodical.
出处 《计算机科学》 CSCD 北大核心 2004年第11期77-79,129,共4页 Computer Science
基金 863资助项目"战略预警与监管体系结构研究"(2002AA142040)
关键词 入侵 攻击 事件 网络安全 误报率 算法 聚类分析 预警方法 趋势预测 预测效果 Intrusion event, Early warning,Prediction,Network security
  • 相关文献

参考文献5

  • 1Baumann R,Plattner C. Honeypots,Diploma thesis. http://security. rbaumann. net/download/diplomathesis. pdf. 2002
  • 2Buchholz F,Thomas E D,Kuperman B,et al. Packet Tracker Final Report, CERIAS Technical Report. Purdue University.http://www. cerias. purdue. edu/infosec/bibtex- archive//archive/2000-23. pdf. 2000
  • 3Rathmell A, Dorschner J, Knights M. Project: Threat Assessment and Early Warning Methodologies for Information Assurance,Http://www. icsa, ac. uk/Projects/ropa. html IAAC, Summary of Research Results: Early Warning & Threat Assessment Methodologies Fo
  • 4Shyhtsun J Y,Felix W,Fengmin G,Ming-Yuh H. Intrusion Detection for an On-Going Attack. http://www. mnlab. cs. depaul.edu/seminar/fall2002/IDSongoing. pdf. 1999
  • 5Ming-Yuh H,Jasper R J,Wicks T M. A Large-scale Distributed Intrusion Detection Framework Based on Attack Strategy Analysis. Computer Networks (Amsterdam, Netherlands), 1999, 31(23-24) :2465-2475

同被引文献88

引证文献11

二级引证文献42

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部