作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (5): 164-166. doi: 10.3969/j.issn.1000-3428.2011.05.055

• 安全技术 • 上一篇    下一篇

基于粗糙集和证据推理的网络入侵检测模型

叶 清1,陈亚莎2,黄高峰1   

  1. (1. 海军工程大学电子工程学院,武汉 430033;2. 北京工业大学计算机科学与技术学院,北京 100124)
  • 出版日期:2011-03-05 发布日期:2012-10-31
  • 作者简介:叶 清(1978-),男,讲师、博士,主研方向:网络安全,网络可生存性;陈亚莎,博士研究生;黄高峰,讲师、硕士

Network Intrusion Detection Model Based on Rough Set and Evidence Theory

YE Qing 1, CHEN Ya-sha  2, HUANG Gao-feng 1   

  1. (1. College of Electronic Engineering, Naval University of Engineering, Wuhan 430033, China; 2. College of Computer Science and Technology, Beijing University of Technology, Beijing 100124, China)
  • Online:2011-03-05 Published:2012-10-31

摘要: 证据推理依赖于专家知识提供证据,要求各证据体相互独立,因此难以应用于实际。针对上述问题,提出基于粗糙集理论的证据获取和基本概率赋值客观确定方法,利用粗糙集中的属性约简算法剔除冗余属性,形成最简属性集,以提高证据合成效率,缩短证据合成时间,减少证据合成的冲突现象。在此基础上建立一个基于粗糙集和证据推理的网络入侵检测模型,通过算例验证该模型检测精度较高、误检率较低。

关键词: 入侵检测, 粗糙集, 证据推理, 基本概率赋值

Abstract: Evidence theory relies on expert knowledge to provide evidences and require evidences independent, which makes it hard to be applied. To solve the problem, this paper proposes a hybrid approach based on rough set theory and evidence theory. In order to obtain Basic Probability Assignment(BPA) for all evidences, a method of getting evidences and objective BPA based on rough set theory is presented to decrease the combination computation and improve the combination efficiency. Conflict evidences are reduced by applying the attribute simplification algorithm of rough set theory to eliminate redundant evidences. A model for network intrusion detection based on rough set theory and evidence theory is provided to show that the hybrid model has high detection precision and low false positive detection rate.

Key words: intrusion detection, rough set, evidence theory, Basic Probability Assignment(BPA)

中图分类号: