作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (14): 158-160. doi: 10.3969/j.issn.1000-3428.2010.14.057

• 人工智能及识别技术 • 上一篇    下一篇

带约束的免疫克隆取证分析方法

杨 珺1,王 敏2,陈 晨1,廖伟辉1,李 晶1   

  1. (1. 武汉大学电子信息学院,武汉 430079;2. 通信指挥学院二系,武汉 430010)
  • 出版日期:2010-07-20 发布日期:2010-07-20
  • 作者简介:杨 珺(1973-),女,讲师,主研方向:信息安全;王 敏,讲师;陈 晨、廖伟辉、李 晶,硕士研究生
  • 基金资助:
    高等学校博士学科点专项科研基金资助项目(2004048 6049)

Immune Clone Forensic Analysis Method with Constraint

YANG Jun1, WANG Min2, CHEN Chen1, LIAO Wei-hui1, LI Jing1   

  1. (1. School of Electronic Information, Wuhan University, Wuhan 430079; 2. Second Department, Commanding Communications Academy, Wuhan 430010)
  • Online:2010-07-20 Published:2010-07-20

摘要: 针对基于关联规则的取证分析方法存在取证效率低的问题,提出带约束的免疫克隆取证分析方法。该方法以抗原对抗体的支持度作为亲和度函数,以关键属性作为约束条件,以最小支持度和最小置信度作为筛选条件,通过对抗体进行免疫克隆操作来构造行为轮廓。实验结果表明,与基于Apriori-CGA算法的取证分析方法相比,该方法的行为轮廓建立时间和行为轮廓规模均明显减小,能够有效地提高取证分析的效率和确立重点调查取证的范围。

关键词: 计算机安全, 计算机取证, 数据挖掘, 免疫克隆, 关联规则

Abstract: Aiming at the problem of low efficiency of the forensic analysis method based on the association rule, this paper proposes an immune clone forensic analysis method with constraint. Taking the support of the antigen to the antibody as the function of affinity, taking the key attribute as the constraint condition and taking the minimal support and the minimal confidence as the screening condition, the behavior profiling is built with the help of the immune clonal operation. Experimental result shows that compared with forensic analysis method based on Apriori-CGA algorithm, the setting up time of behavior profiling and the scale of behavior profiling of the method are remarkably reduced, it can effectively improve the efficiency of forensic analysis and confirm the range of electronic crime investigation.

Key words: computer security, computer forensic, data mining, immune clone, association rules

中图分类号: