由于网络入侵检测系统的实时性要求,将传统的关联规则挖掘算法直接应用到入侵检测系统中,运行效率往往不能满足实际的需要。考虑到网络审计日志实时更新的特点,提出了一种基于深度优先生成树的关联规则挖掘的改进算法FIDF,它改变了候选项集的产生顺序,优先寻找最大频繁项集。该算法只需扫描一次数据库,且当事务数据库和支持度阈值改变时,无需重新扫描数据库,提高了审计日志数据关联规则挖掘的效率,确保了入侵检测系统的实时性和准确性。
Because of real-time requirement of the network intrusion detection system,applying the traditional association rule mining algorithm to the intrusion detection system will not meet the actual needs.Considering real-time update feature of the network audit records,the algorithm FIDF based on depth-first spanning tree is put forward.The algorithm changes the order of candidate itemsets generation,first to find maximal frequent itemsets.It only scans the database once,and when the transaction database and the support threshold are changed,it is no need to rescan the database,which improves the efficiency of audit record association rules mining and ensures the real-time and accuracy demand of intrusion detection system.