作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (4): 159-161. doi: 10.3969/j.issn.1000-3428.2009.04.056

• 安全技术 • 上一篇    下一篇

增量式关联分类方法在病毒检测中的应用

庄蔚蔚1,叶艳芳2,姜青山1,韩智雪2   

  1. (1. 厦门大学软件学院,厦门 361005;2. 厦门大学计算机系,厦门 361005)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-02-20 发布日期:2009-02-20

Application of Incremental Associative Classification Method in Malware Detection

ZHUANG Wei-wei1, YE Yan-fang2, JIANG Qing-shan1, HAN Zhi-xue2   

  1. (1. School of Software, Xiamen University, Xiamen 361005; 2. Department of Computer, Xiamen University, Xiamen 361005)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-02-20 Published:2009-02-20

摘要: 传统关联规则挖掘算法主要基于支持度-可信度构架,时空开销的限制使其无法深入挖掘非频繁项集。目前对带类属性的关联分类增量学习研究较少,该文提出一种新的增量式关联分类方法,解决了带类属性数据的增量学习问题,在数据频繁更新时,实现有限时空开销下关联规则的快速提取和维护。实验结果表明,该方法能有效维护并更新关联规则,避免重复学习历史样本,保证分类模型的预测能力。

关键词: 关联分类规则, 增量学习, 病毒检测

Abstract: Traditional associative rule mining algorithm is mostly based on the support-confidence framework, which disable the in-depth study of frequent items for time and space limitations. There is few study of associative classification incremental learning currently. This paper presents a new incremental associative classification method, which can solve the incremental learning problems of data with class attribute, and realize the fast extraction and maintenance of associative rule with limited time and space when the data is updating frequently. Experimental results show that this method can quickly and effectively maintain and update the classification rules, which avoid re-learning the history samples and ensure the predictability of the classification model.

Key words: associative classification rule, incremental learning, malware detection

中图分类号: