摘要
为了提高检测效率并减小误报率,提出了一种基于免疫算法和诱捕技术的网络入侵检测模型。在诱捕服务器中提取记录进行格式转换,然后在否定选择算法中引入诱捕服务器的记录,以代替部分随机生成数据,即把误用检测和异常检测结合起来,将目前的独立配合模式改为相互联系的配合模式,充分利用各自独立的系统数据资源并使之共享,最后通过算法分析和模拟实验,证明了该系统具有较高的正确率和较低的误报率。
In order to improve the efficiency ofdetection and reduce the false positive rate, one kind ofintrusion detection model is pro- posed based on immunity algorithm and deception technology. The format ofthe records ofdeception server is changed at first, andthen the records of deception server in negative selection algorithm is used to replace of part of data which generated at random. In another word, it' s connection between misuse detection and anomaly detection. And present independent coordinate pattern is changed to a related pattern, each independent system data resources is used and shared. The result shows that this system has high detection rate and low false positive rate by the analysis of algorithms and experiment.
出处
《计算机工程与设计》
CSCD
北大核心
2008年第19期4917-4919,4925,共4页
Computer Engineering and Design
基金
湖南省教育厅科研基金项目(06C115)
关键词
入侵检测
免疫原理
诱捕技术
非随机
否定选择
intrusion detection
immune principle
deception technology
not at random
negative selection