摘要
根据入侵检测中协议分析技术与聚类数据挖掘技术各自不同的检测特点,提出了一种新的入侵检测方法,将协议分析技术融合到聚类数据挖掘中。通过数据清洗和协议分析不但可以有效减少聚类挖掘的数据量,快速地检测出入侵行为,而且可以让被挖掘的数据更加符合聚类数据挖掘的先决条件,提高了聚类数据挖掘检测的效率。
Because of the altitudinal regularity of the network protocol of the data package,a new intrusion detection method is suggested,in order to improve the efficiency.The protocol analysis technique is suggested to be attached to the clustering data mining method.On the one hand,it can take out the illegal data efficiently by reducing the amount of data set which is to be clustered,on the other hand,it can make the data set measure up the hypothesis of the clustering data mining technique,and make the work more efficient.
出处
《计算机工程与应用》
CSCD
北大核心
2009年第14期81-83,共3页
Computer Engineering and Applications
基金
国家自然科学基金No.60773083
广东省科技计划项目(No.2006B15401002)~~
关键词
入侵检测
数据挖掘
聚类
协议分析
intrusion detection
data mining
clustering
protocol analysis