论文部分内容阅读
大部分入侵检测系统的实现都会产生大量的报警信息,在一定程度上影响了系统管理,误报率也较高,影响了入侵检测的效果.针对这个问题,提出了一种基于节点关联的报警置信度计算方法,位于对等网络之上,节点在收到一系列入侵报警之后,需要进行节点关联,从而对报警信息进行融合,提取有效报警信息.其中根据关联对象的不同,节点关联又包括报警关联和信任关联两个层次,报警关联可用来判断入侵报警的有效性,信任关联可用来判断发起报警节点的可信性,给出了相关算法.仿真实验表明,使用该报警置信度计算方法可以提高入侵报警的检测准确率.
Most of the intrusion detection system will generate a large number of alarm information, affecting the system management to a certain extent, the false alarm rate is also high, affecting the effect of intrusion detection.To address this issue, a node-based alarm Confidence calculation method, located above the peer-to-peer network, nodes receive a series of intrusion alarm, the need for node association, so as to fuse the alarm information to extract effective alarm information.According to the different objects, the node association includes Alarm correlation and trust association.The alarm correlation can be used to judge the validity of the intrusion alarm.The trust association can be used to judge the credibility of the alarm node.The algorithm is given.The simulation results show that using the alarm confidence calculation method Can improve the detection accuracy of intrusion alarm.