摘要
在将给定网络数据包文件解协为网络连接记录基础上,针对训练与测试数据集比例划分、分类属性选择和统计属性时间窗大小对网络异常检测模型的影响进行了全面的实验研究。在网络数据包数量较小的前提下,合理选择训练与测试数据集比例、时间窗和统计属性,能够有效地提高异常检测模型对未知攻击的检测能力。
Comprehensive experiment research has been completed on the basis of restoring the network packets into connection records by protocol resolutions,to consider influences of partition of the training and test sets,attribute selection and time window size on anomaly detection model.When the network packets in number are less the detection capability of anomaly model can be evidently increased by partitioning the training and test sets,selecting attributes and time window size in reason.
出处
《计算机工程与应用》
CSCD
北大核心
2004年第23期145-147,共3页
Computer Engineering and Applications
基金
山西省自然科学基金项目(编号:20041047)资助
关键词
网络安全
入侵检测
协议解协
连接记录
统计属性
网络监听软件
network security,intrusion detection,protocol resolution,connection record,statistical attribute