Detecting network intrusions by data mining and variable-length sequence pattern matching

来源 :Journal of Systems Engineering and Electronics | 被引量 : 0次 | 上传用户:xuxinhuiaishu
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Anomaly detection has been an active research topic in the field of network intrusion detection for many years. A novel method is presented for anomaly detection based on system calls into the kernels of Unix or Linux systems. The method uses the data mining technique to model the normal behavior of a privileged program and uses a variable-length pattern matching algorithm to perform the comparison of the current behavior and historic normal behavior, which is more suitable for this problem than the fixed-length pattern matching algorithm proposed by Forrest et al. At the detection stage, the particularity of the audit data is taken into account, and two alternative schemes could be used to distinguish between normalities and intrusions. The method gives attention to both computational efficiency and detection accuracy and is especially applicable for on-line detection. The performance of the method is evaluated using the typical testing data set, and the results show that it is significantly better than the anomaly detection method based on hidden Markov models proposed by Yan et al. and the method based on fixed-length patterns proposed by Forrest and Hofmeyr. The novel method has been applied to practical hosted-based intrusion detection systems and achieved high detection performance. Anomaly detection has been an active research topic in the field of network intrusion detection for many years. A novel method is presented for anomaly detection based on system calls into the kernels of Unix or Linux systems. The method uses the data mining technique to model the normal behavior of a privileged program and uses a variable-length pattern matching algorithm to perform the comparison of the current behavior and historic normal behavior, which is more suitable for this problem than the fixed-length pattern matching algorithm proposed by Forrest et al. At the detection stage, the particularity of the audit data is taken into account, and two alternative schemes could be used to distinguish between normalities and intrusions. The method gives attention to both computational efficiency and detection accuracy and is especially applicable for on-line detection. The performance of the method is evaluated using the typical testing data set, and the results show that it is signif icantly better than the anomaly detection method based on hidden Markov models proposed by Yan et al. and the method based on fixed-length patterns proposed by Forrest and Hofmeyr. The novel method has been applied to practical hosted-based intrusion detection systems and achieved high detection performance.
其他文献
【内容摘要】在高中物理课程的教学中,教师要有意识的让课堂教学紧密联系学生的生活。首先,教师可以巧用生活实例来解释相关的理论知识,这种灵活的教学方式通常能够收获不错的教学成效。同时,模拟一些具体的生活场景同样是深化知识教学与学生生活间的联系的一种很好的教学方式,这种模式也能够帮助大家对于相关知识点有更好的体会。此外,教师要善于巧用物理学知识来帮助大家解决生活中的一些问题,这将会帮助大家更好的体会到物
2015年11月29日今天中午,娇娇和弟弟只顾着玩,不睡午觉,我借机让娇娇哄弟弟入睡。我“利诱”娇娇说:“如果你可以帮妈妈把弟弟哄睡,妈妈奖励你一个奶片。”娇娇很高兴,马上用
作者简介:齐大辉,现任北京大学文化研究与发展中心研究员、北京大学汇丰商学院EMBA后财富中心主任教授、北京大学家庭文化与家长教育研究所所长、北京书同教育科技研究院院长。  齐大辉先生是中国家长教育学术带头人,是“国民素质从娃娃抓起,娃娃素质从家长抓起”“抓党建促家建,正家风助党风”源头教育思想的提出者。  家的呼唤  随着我国改革开放的深入与市场经济的完善,我们的物质生活越来越来丰富。但与此形成强
1.临睡前的一个吻孩子临睡前的一个吻,孩子遇到困难时轻拍他们肩头的手,孩子受了委屈时一个温暖的怀抱,孩子回家时的一个问候,还有一句“爸爸妈妈爱你”的表达。这是我们了解
在社会有机体中,诚信具有道德性和制度性两种特性,具有维护社会秩序的独特价值。运用社会有机体理论解读诚信缺失现象,不难发现我国当前诚信呈现“空心化”状态,即传统诚信缺
【内容摘要】在高中数学课程的教学中,教师所使用的教学语言将会直接影响到整堂课的教学成效。在教学主题引入时教师可以使用灵活多样的暖场语,并且要注重对于教学主题的突出。在知识导入时教师所使用的导入语应当注重对于学生思维的激发,这样才能够促进学生对于知识的理解与吸收。在进行知识讲授时教师所使用的教学语言务必做到准确与规范,尤其是对于一些概念、定理、定律在展开阐述与论证时语言一定要准确而清晰。这样才能够让
数学是一门逻辑性、抽象性较强的学科。在以前的教学过程中,教师往往采用“填鸭式”的教学方法来开展教学活动,然而这种教学方法却存在着一系列问题,具体的问题表现如下:单一
侯宝林:不达目的不罢休语言大师侯宝林只上过三年小学,由于勤奋好学,他的艺术水平达到炉火纯青的程度,成为著名的语言专家。有一次,他为了买到一部明代笑话书《谑浪》,跑遍北
学生阅读能力的培养必须抓住“读”字,使学生在读中理解语文文字,理解课文内容,提高阅读能力。阅读时要抓住书中的精髓,实现由浅入深的转化。阅读时,要取其精华,去其糟粕。通
语言是人类交际的重要工具。作为课堂教学,都要运用语言的形式向学生传道、授业、解惑。因此,教师的语言表达能力直接影响着教学的效果。要提高教学质量,就必须研究教学语言