建立了基于粗糙集理论的入侵检测灰色空间模型,根据信息增益设计等价类获取和约简算法,提出了一种新的入侵检测系统模型。运用KDDCUP99数据集对网络入侵检测进行了测试。分析和对比实验结果表明,该模型具有分类规则简单、检测时间短和准确率高等特点,克服了检测系统不能有效判别未知行为的瓶颈。
An intrusion detection gray space model is presented based on rough set theory.Information gain is used to equivalence rule discovery and reduction algorithm.As a result,a new intrusion detection model is designed.According to the analyses and validation based on KDDCUP 99,the experimental results show that the model is good for networks intrusion detection with simple classification rules,short detection time and high detection accuracy,and it overcomes the bottleneck that the detection system can not effectively determine the unknown behavior.