摘要
通过采集主机中三个不同层次的特征数据,利用SOM-PAK,训练出三个表示系统正常模式的MAP,并确定报警阈值的选取方法.在对运行入侵工具NMAP和HYDRA时的检测中,通过连续检测多组数据,显著提高了系统检测率.
This paper uses SOM _ PAK to train three normal MAP of system on characteristic datas of different layer and decides the method of choosing alert threshold. When decting system abnormity by intrusion tools NMAP and HYDRA, the system indicates that the accuracy of detecting the intrusion is greatly improved by means of detecting multiple data continuously.
出处
《南开大学学报(自然科学版)》
CAS
CSCD
北大核心
2006年第3期104-109,共6页
Acta Scientiarum Naturalium Universitatis Nankaiensis
基金
国家自然科学基金(66272011)