摘要
高虚警率和漏警率是当前入侵检测系统(IDS)的主要问题。采用基于CBW关联规则的数据挖掘算法,提出了一种新的分布式入侵检测模型,并分析了各模块的具体功能与实现。经实验分析,本模型可以有效降低虚警率和漏警率,同时在一定程度上实现各分节点间的快速协作检测能力。
High rate of false alarms and missing alarms are the primary problem in current intrusion detection system (IDS). In this paper, a new model of distributed intrusion detection is proposed,which is based on CBW association rules algorithm to mine new rules and intrusion event, and the function and implement of each module is analyzed. The experiment result showed that this model could decrease false alarms rate and missed alarms rate effectually, this model could also improve detection speed and realize the cooperation among each code.
出处
《微处理机》
2008年第1期103-106,共4页
Microprocessors
基金
国家自然科学基金资助项目(60373088)
关键词
入侵检测
数据挖掘
关联规则
Intrusion detection
Data mining
Association rules