论文部分内容阅读
KDDCUP99数据集中网络连接特征属性种类多,提取难度大,给研究人员将数据集应用到真实网络环境中造成很大困难。同时因为数据集产生年代久远,其中的攻击手段和特征属性对于当下复杂的网络环境已经过时,因此迫切需要提取新的网络连接特征,应用新型攻击手段,制作出更符合真实网络环境的数据集。通过对数据集制作方法的深入研究,给出了提取网络连接特征的具体方法,进而设计出一套基于此数据集的入侵检测系统。同时也为今后的研究中,制作新的入侵检测数据集提供了参考。
There are many characteristics of network connection in KDDCUP99 dataset, so it is very difficult to extract the dataset. It is very difficult for researchers to apply the dataset to the real network environment. At the same time, because of the generation of datasets, the methods of attack and the attributes of attributes are obsolete for the current complex network environment. Therefore, it is urgent to extract new characteristics of network connection and apply new attack methods to create datasets that are more in line with the real network environment. Through in-depth research on the method of data set creation, this paper gives a concrete method of extracting network connection characteristics, and then designs a set of intrusion detection system based on this data set. At the same time, it also provides a reference for making new intrusion detection datasets for future research.