摘要
根据操作系统的工作原理,对计算机执行程序的行为特征进行严密地入侵剖析。运用马尔可夫模型对计算机受到入侵时的状态建立合适粒度的状态知识源,采用模糊D-S证据论方法来融合所建立的状态知识源进行综合评判,解决了入侵检测过程多源数据融合常涉及到非排斥性假设和操作不确定性的数据所造成的误检和漏检率。经过实验分析,该方法有效地降低了误检和漏检率,提高了入侵检测的全面性和准确性。
Aiming at the behavior and characteristic of the computer execution of processes,take a rigorous analysis of the computer invaded based on the operation principles of the operating system.This method is to build state knowledge sources of appropriate granularity for the intrusion by using of Markov model and combine the prescriptive state knowledge sources based on the obscure dempster-shafter evidence theory.It can reduce the proportion of mistaken detection and that of missing detection of data of no exclusion hypothesis and undefined operation by the multi-sources data fusion.Through experimental analysis,this method improves the completeness and the accuracy of the invasion detection.
出处
《计算机工程与应用》
CSCD
北大核心
2007年第22期154-157,共4页
Computer Engineering and Applications
基金
甘肃省自然科学基金(the Natural Science Foundation of Gansu Province of China under Grant No.ZS021-A25-018-G)。