摘要
分析了目前入侵检测系统存在的错报、漏报等问题,阐述了在网络入侵检测系统中运用数据挖掘技术的基本原理,提出了基于数据挖掘的入侵检测框架模型,探讨了通过对网络连接特性的挖掘来提高警报准确率以及检测未知入侵的方法,最后设计了一个对网络连接性能参数进行数据挖掘的分类算法,并对其具体实现过程进行了描述。
The problems of false negatives and false positives in intrusion detection system are analyzed in this paper. According to the principles of data mining, an Intrusion detection frame based on the technologies of data mining is brought out then. The methods that mine the data of network connection properties to improve the veracity of alerts of IDS are discussed and a data classification algorithm is described and realized.
出处
《武汉工业学院学报》
CAS
2005年第3期31-34,共4页
Journal of Wuhan Polytechnic University
关键词
入侵检测
数据挖掘
决策树
intrusion detection system
data mining
decision tree