Intrusion Detection System, Based On Abnormal Patterns | | Posted on:2005-05-15 | Degree:Master | Type:Thesis | | Country:China | Candidate:H Liu | Full Text:PDF | | GTID:2208360125457141 | Subject:Computer application technology | | Abstract/Summary: | | | Intrusion Detection System is a security technology to detect the intrusion through monitoring the system or network in runtime. Based on the research on the intrusion detection technology and intrusion method in common use, a solution of runtime anomaly-based Intrusion Detection System is proposed in the paper. Aimed at the characteristics of current situation of network intrusion and attacks, the system monitors the data packet through statistic means incorporating association analysis algorithm in data mining method to analyze the connection record.In connection record analysis, the standard Apriori algorithm is modified and the influence caused by outlying factors is eliminated according to the circumstantialities in intrusion detection, whose validity and feasibility is appoved by field test. An intrusion detection mechanism adapted to the current circumstances with high bandwidth and large flow is proposed, which can enhance the intrusion detection speed and lower the system resources usage.The average data packet flow received and sent in every time-interval by every computer in network is acquired with dynamic updating through statistics means, with which the flow anomaly detection is conducted by contrasting the current flow. The field test proved that the packet flow monitoring is able to effectively detect the network flow anomaly caused by most of Denial of Services attack, which attacks the network through depleting the band width and system resource and makes up for the deficiency of association analysis algorithm. | | Keywords/Search Tags: | IDS, anomaly, data mining, association rule, data flow | | Related items |
| |
|