随着Internet网络的快速普及,针对计算机及网络基础设施的攻击已经成为了一个越来越严重的问题.针对入侵检测技术提出了一种基于敏感时间滑窗的检测算法STSW,扩展了数据挖掘在入侵检测中的应用.以KDDCUP99作为实验数据研究了参数的选取对检测效果的影响,将该算法的执行效率与基于SPADE挖掘序列模式的入侵检测算法进行了对比.结果表明:入侵检测算法可以取得比较满意的检测效果,并且执行效率要优于基于SPADE的入侵检测算法.
With the wide spread of Internet, the attacks against computers and network infrastructures have become an increasingly serious problem. Aiming at the detection technology, we present a detection atsorithm STSW based on a time-sensitive sliding window, which expands the application of data mining in intrusion detection. Using KDD CUP99 as experimental data, the paper studied the effect of selection of different parameters on detection results. The efficiency of the presented algorithm was compared with that of the algorithm based on SPADE mining sequence patterns. Experimental results show that the presented intrusion detection algorithm can get quite satisfactory effect. The performance efficiency of the algorithm in this paper is better than that of the algorithm based on SPADE.