期刊文献+

基于DFA的HTTP会话学习模型 被引量:2

A HTTP Session Learning Model based on DFA
原文传递
导出
摘要 由于Web应用涉及范围广,结构复杂多变等特点,对其采用的入侵检测面临着严峻的考验。具有学习功能的入侵检测有着广阔的研究前景。提出一种异常检测方法,从HTTP连接中提取HTTP会话,按照RFC标准描述HTTP请求,以此构建基于DFA的HTTP会话学习模型。并针对HTTP请求数量庞大的特点,提出模型简化的算法。该模型能够实现自动更新,有助于解决入侵检测保护Web应用时遇到的问题。 The protection of Web server-based applications by using intrusion detection, for their large, complex structure are faced with severe test. Intrusion detection with learning function has the potential to improve the state of affair. This paper describes how HTTP sessions are extracted from HTTP connections, and how DFA is introduced to build a model for HTTP sessions according to HTTP requests in RFC format. For the large size of HTTP requests, a algorithm for model simplification is proposed. The model maintains the feature of automatic updating, and this could serve as a strategy to meet the requirements for protecting Web applications.
作者 申茜 马进
出处 《信息安全与通信保密》 2010年第4期87-89,共3页 Information Security and Communications Privacy
基金 国家自然科学基金资助项目(批准号:60903191) 国家高技术研究发展计划(863)资助项目(编号:2007AA01Z457)
关键词 超文本传输协议 会话 确定性有限自动机 异常检测 HTTP sessiofi DFA anomaly detection
  • 相关文献

参考文献1

二级参考文献7

  • 1[3]Lippmann R;Cunningham R. Improving intrusion detection performance using keyword selection and neural network[C]. Proceedings. RAID'99,1999
  • 2[4]Lee, S.C.; Heinbuch, D.V. Training a neural-network based intrusion detector to recognize novel attacks[J]. IEEE Transactions on Systems, Man and Cybernetics, Part A, Volume: 31 Issue: 4 , July 2001, pp 294 -299
  • 3[5]J Balasubramaniyan, J Omar Garcia-Fernandez, D Isacoff, E Spafford, D Zamboni. An architecture for intrusion detection using autonomous agents[C].Proceedings of the 14th Computer Security Applications Conference, 1998. pp 13-24
  • 4[6]Frincke D, Don Tobin, Jesse McConnell et al. A framework for cooperative intrusion detection[C]. Proceedings of the 21st National Information Systems Security Conference, 1998, pp 361-373
  • 5[7]Jungwon Kim; Bentley, P.J. Towards an artificial immune system for network intrusion detection: an investigation of clonal selection with a negative selection operator[C] .Proceedings of the 2001 Congress on Evolutionary Computation. Volume: 2 , 2001, pp1244 -1252
  • 6蒋建春,马恒太,任党恩,卿斯汉.网络安全入侵检测:研究综述[J].软件学报,2000,11(11):1460-1466. 被引量:370
  • 7胡华平,陈海涛,黄辰林,唐勇.入侵检测系统研究现状及发展趋势[J].计算机工程与科学,2001,23(2):20-25. 被引量:53

共引文献15

同被引文献8

引证文献2

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部