期刊文献+

基于级联AdaBoost的Snort异常检测预处理插件研究 被引量:1

Research on Snort Anomaly Intrusion Detection Preprocessor Plug-in Based on Cascade AdaBoost
下载PDF
导出
摘要 在开源网络入侵检测系统Snort的预处理阶段加入了一种新的预处理插件,插件中使用改进的AdaBoost算法进行异常网络流量的特征提取和构造每一级AdaBoost分类器,然后用级联的结构将多个AdaBoost分类器做线性组合共同完成入侵检测,组合系数通过自适应学习得到。实验表明,该插件可以有效地检测Snort规则集中无可匹配特征的异常网络流量,降低Snort系统对于异常流量检测的漏报率和误报率,满足高速网络环境对入侵检测实时性的要求。 A new preprocessor plug-in is added to an open source network intrusion detection system named Snort.An improved Adaboost algorithm is used in this plug-in to select anomaly network traffic features and to construct each Adaboost classifier at different level,then several Adaboost classifiers are combined in linear combination manner to complete intrusion detection task,the combine coefficients can be learned by adaptive learning method. Experimental results show that this plug-in can efficiently detect anomaly network traffics which do not have matched signatures in snort rules,it can also decrease snort's false negative rate and false positive rate for anomaly network traffic detection and satisfy the real-time demand to intrusion detection system in high speed network environment.
作者 张雪松
出处 《科学技术与工程》 2011年第17期3997-4001,共5页 Science Technology and Engineering
关键词 网络入侵检测 级联AdaBoost 预处理器 network intrusion detection cascade AdaBoost preprocessor
  • 相关文献

参考文献5

  • 1(美)J Koziol J著,吴浦峰,孙默,许诚,等译.Snort入侵检测实用解决方案.北京:机械工业出版社,2005. 被引量:1
  • 2Caswell B,Beale J,Foster J C,等著.宋劲松,等译.Snort2.0入侵检测.北京:国防工业出版社:2004. 被引量:2
  • 3Freund Y, Schapire R E. A decision-theoretic generation of online learning and an application to boosting. Journal of Computer and System Science, 1997 ;55 ( 1 ) : 119-139. 被引量:1
  • 4Viola P, Jone M J. Robust real-time face detection. International Journal of computer vision,2004 ;57 (2) : 137-154. 被引量:1
  • 5Friedman J, Hastie T, Tibshirani R. Additive logistic regression: A statistical view of boosting. Ann Statist , 2000, 28 (2) : 337-407. 被引量:1

共引文献1

同被引文献4

  • 1Caswell B,Beale J,Foster J C,等著.宋劲松,等译.Snort2.0入侵检测.北京:国防工业出版社:2004. 被引量:2
  • 2(美)Jack Kozi01.snort入侵检测实用解决方案.吴浦峰,孙默,许诚,等译.北京:机械工业出版社,2005. 被引量:1
  • 3武旭东.snon入侵检测系统研究与应用.长春:吉林大学,2011. 被引量:1
  • 4Haines J A, Rossey L M, Lippmann R P, et al. Extending the DAR- PA offLine intrusion detection evaluations. In:Darpa Information Survivability Conferenceand Exposition (DISCEX) II. U. S. A ,2001, 77-88. 被引量:1

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部