位置:成果数据库 > 期刊 > 期刊详情页
基于隐Markov模型的协议异常检测
  • ISSN号:1000-1239
  • 期刊名称:《计算机研究与发展》
  • 时间:0
  • 分类:TP393[自动化与计算机技术—计算机应用技术;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]北京交通大学计算机与信息技术学院,北京100044
  • 相关基金:国家自然科学基金项目(60442002);北京交通大学校科技基金项目(2006XM007)
中文摘要:

入侵检测是网络安全领域的研究热点,协议异常检测更是入侵检测领域的研究难点.提出一种新的基于隐Markov模型(HMM)的协议异常检测模型.这种方法对数据包的标志位进行量化,得到的数字序列作为HMM的gray,从而对网络的正常行为建模.该模型能够区分攻击和正常网络数据.模型的训练和检测使用DARPA1999年的数据集,实验结果验证了所建立模型的准确性,同现有的基于Markov链(Markov chain)的检测方法相比,提出的方法具有较高的检测率.

英文摘要:

Protocol anomaly detection, a new technique of anomaly detection, has great research value. Its incorporation with hidden Markov model (HMM) is still in infancy. In order to investigate the capabilities of hidden Markov model in this area, a protocol anomaly detection model based on HMM is given in this work. Firstly, an overview of anomaly detection is presented with emphasis on the issues about protocol anomaly detection. Then, a novel protocol anomaly detection model based on HMM is proposed. This method filters incoming TCP traffic by destination ports and then quantizes network flags into decimal numbers. These numbers are classified into sequences which are used as inputs of HMMs by TCP connections. Detection models based on HMM representing normal network behaviors are trained by Baum-Welch method. Finally, the models' correctness and effectiveness is demonstrated by using forward method on MIT Lincoln Laboratory 1999 DARPA intrusion detection evaluation data set. Forward method is used here to compute the probability of a connection. Threshold K is designed to control detection rate. By comparing the probability with threshold K, this protocol anomaly detection model could find whether the traffic is normal or containing some sort of anomaly. Experimental results show that the model based on HMM has higher detection rates on attacks than the Markov chain detection method.

同期刊论文项目
同项目期刊论文
期刊信息
  • 《计算机研究与发展》
  • 中国科技核心期刊
  • 主管单位:中国科学院
  • 主办单位:中国科学院计算技术研究所
  • 主编:徐志伟
  • 地址:北京市科学院南路6号中科院计算所
  • 邮编:100190
  • 邮箱:crad@ict.ac.cn
  • 电话:010-62620696 62600350
  • 国际标准刊号:ISSN:1000-1239
  • 国内统一刊号:ISSN:11-1777/TP
  • 邮发代号:2-654
  • 获奖情况:
  • 2001-2007百种中国杰出学术期刊,2008中国精品科...,中国期刊方阵“双效”期刊
  • 国内外数据库收录:
  • 俄罗斯文摘杂志,荷兰文摘与引文数据库,美国工程索引,日本日本科学技术振兴机构数据库,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版),中国北大核心期刊(2000版)
  • 被引量:40349