摘要
为了实现高速网络环境下的入侵检测,对入侵检测的机理进行探讨,将入侵检测归结于不完备数据集上的推理过程,提出知识库的相似度、完备度等概念,并用其对知识库的规模和增长速度进行控制,从而保证入侵检测在有限规模的空间中进行搜索。同时,采用信息增益等方法将入侵检测转换到低维空间上进行。实验结果表明上述方法有效降低了入侵检测系统的计算负荷,提高了其实时响应性能。
In order to detect intrusions of high-speed network,the mechanism of intrusion detection is discussed.Intrusion detection is reduced to an inference procedure on an incomplete data set.The concepts of self-similarity degree and completeness degree of the knowledge base are proposed.They are used to control the scale and increasing speed of the knowledge base so that intrusion detection is assured to be proceeded in a limited space.At the same time,information gain is used to make intrusion detection to running in a lower space.The experiments show that the proposed method reduces the calculation load of intrusion detection systems effectively and enhances its real time performance.
出处
《计算机工程与应用》
CSCD
北大核心
2009年第17期88-90,112,共4页
Computer Engineering and Applications
基金
上海工程技术大学科研基金项目(No.07-22)
上海市教委科研创新项目(No.09YZ370)~~
关键词
计算机网络
信息安全
入侵检测
computer network
information security
intrusion detection
作者简介
史志才(1964-),男,博士,教授,CCF高级会员,主要研究领域:计算机网络与信息安全,图形图像处理。