作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (3): 181-182. doi: 10.3969/j.issn.1000-3428.2008.03.063

• 安全技术 • 上一篇    下一篇

基于HMM和STIDE的异常入侵检测方法

孙 彦,李永忠,罗军生   

  1. (江苏科技大学电子信息学院,镇江 212003)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-02-05 发布日期:2008-02-05

Hybrid Anomaly Intrusion Detection Method Using HMM and STIDE

SUN Yan, LI Yong-zhong, LUO Jun-sheng   

  1. (School of Information, Jiangsu University of Science and Technology, Zhenjiang 212003)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-02-05 Published:2008-02-05

摘要: 入侵检测是对正在发生或已经发生的入侵行为的一种识别过程。异常检测是入侵检测的主要分析方法之一。该文在传统的使用单一入侵检测算法的基础上,提出一种基于HMM和STIDE复合算法的异常入侵检测方法。HMM和STIDE复合算法被用来区分未知的行为是合法操作还是一次入侵。实验证明该方法具有低虚警率和高检测率。

关键词: 入侵检测, 异常检测, HMM方法, STIDE方法

Abstract: Intrusion detection is a process of identify the intrusion which had happened or not. Anomaly detection method is one of the main intrusion detection methods. Based on the traditional intrusion detection algorithm using single intrusion detection method, a hybrid method which combines HMM with STIDE is proposed. The HMM along with STIDE is used to categorize an unknown behavior to be either normal or an intrusion. Experimental results prove the hybrid method in low false positive rate with high detection rate.

Key words: intrusion detection, anomaly detection, Hidden Markov Model(HMM), Sequence Time Delay Embedding(STIDE)

中图分类号: