在网络入侵发生的早期进行检测对于提高在线入侵检测系统的实时性至关重要。针对网络入侵的早期检测,提出一组描述网络入侵早期行为的特征,设计早期特征在线提取算法。采用GHSOM神经网络算法作为分类器,实现基于神经网络的在线入侵早期检测系统。实验结果证明,该方法对绝大多数攻击的早期检测率在80%以上。与非早期检测相比,可优化在线检测的实时性,提高检测率。
It is important to improve the real-time of online intrusion detection system in the early stage of network intrusion. Aiming at the early detection on network intrusion that detects the anomaly traffic at beginning phase of network attack, feature is extracted to describe the behavior of network invasion, and the algorithm of extraction is designed. An online intrusion detection system is represented based on the algorithm of GHSOM. Experimental result proves that most attacks' early detected ratio is above 80% used by this method, and early detection optimizes speed and efficiency of online intrusion detection system.