摘要
介绍了入侵检测系统和数据挖掘技术的概念、特点和关键技术,分析了入侵检测系统中信息收集的主要数据来源,结合传统的入侵检测方案的缺点,提出了一种基于数据挖掘技术的具有自我学习、自我发展能力的入侵检测系统的体系结构模型,此模型针对不同的信息来源应用不同的数据挖掘方法进行识别。
In this paper, the conception, the characteristic and key technique of Intrusion Detection System and Data Mining are introduced. And the main data source of information collection in the Intrusion Detection System is analyzed. This paper combines the shortcoming of the framework of traditional Intrusion Detection, and also specifies a framework of a self-training and self-development Intrusion Detection System based on Data Mining. The framework adopts different methods of Data Mining to identify according to different information.
出处
《电子科技大学学报》
EI
CAS
CSCD
北大核心
2002年第5期502-506,共5页
Journal of University of Electronic Science and Technology of China
基金
总装备部预研基金资助项目