作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (04): 137-139. doi: 10.3969/j.issn.1000-3428.2007.04.047

• 安全技术 • 上一篇    下一篇

B/S信息系统的入侵检测研究

谢丽霞1,杨宏宇2,3   

  1. (1. 中国民航大学计算机学院,天津 300300;2. 中国民航大学软件技术研究中心,天津 300300; 3. 中国民航大学天津市智能信号与图像处理重点实验室,天津 300300)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-02-20 发布日期:2007-02-20

Research on Intrusion Detection for B/S Information System

XIE Lixia1, YANG Hongyu 2,3   

  1. (1. School of Computer Science, Civil Aviation University of China, Tianjin 300300; 2. Software Research Center, Civil Aviation University of China, Tianjin 300300; 3. Tianjin Key Lab for Advanced Signal Processing, Civil Aviation University of China, Tianjin 300300)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-02-20 Published:2007-02-20

摘要: 提出了针对B/S数据服务系统的入侵检测模型。该模型采用两层结构:第1层分析不同来源的安全数据并生成预警条件,第2层对预警数据进行处理并作出是否警报的最终决定。在模型中引入了树型拓扑结构,为服务器端的正常行为建模,用不同的安全相关数据生成历史轮廓,通过有序归并和基于通用序列模式(GSP)的Apriori验证发现异常行为。该方法对报警情况和报警自身进行综合分析,具有较高的检测率。

关键词: 入侵检测, 轮廓, 归并, 验证, 通用序列模式

Abstract: An intrusion detection model against attacks to B/S data service system is presented. This model consists of two layers, layer one analyzes security-relevant data from different sources and generates pre-alarm conditions, layer two processes such data and makes final decisions. A tree topology is used in the process of server behavior abstract description, consequently generates historical profile with different security related data. Anomaly behaviors among operations are detected through orderly merge and verification with Apriori algorithm based on general sequential pattern (GSP). The experimental results show that the model integrates alarm conditions with alarm contents and has high intrusion detection ratio.

Key words: Intrusion detection, Profile, Mergence, Verification, General sequential pattern(GSP)