针对目前网络入侵检测系统中,大多数网络异常检测技术仍存在误报率较高、对建立检测模型的数据要求过高、检测率不高等问题。从用户的传输行为出发,研究体现用户行为的数据报文中的IP地址、端口号、报文类型、报文长度,对异常检测的需求、审计数据的具体特征进行分析,提出了一种基于最近邻策略的用户传榆行为入侵检测算法-IDNN算法。通过仿真实验,表明IDNN算法在针对不同用户应用服务行为的入侵检测中效果明显。
In the field of network intrusion detection,there are some problems such as high false alarm rate,requirement of high quality data for modeling the normal patterns and the deterioration of detection rate for network anomaly detection.This paper presents an intrusion detection algorithm based on nearest neighbor strategy in user transport behavior(IDNN),from the user's transmission behavior, it researches the IP address, port number, datagram type for user's datagram, and analyzes the demand for anomaly detection, the specific characteristics of audit data.The experiment demonstrates that the effect of IDNN algorithm is obvious for different users' applications services behavior in the intrusion detection.