全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Intrusion detection framework based on network security knowledge databases
基于网络安全知识库的入侵检测模型

Keywords: network security,knowledge datasets,intrusion detection framework,correlation,threat evaluation
网络安全
,知识库,入侵检测模型,关联,威胁评估

Full-Text   Cite this paper   Add to My Lib

Abstract:

A new intrusion detection framework based on the existing network security knowledge databases was This paper proposed a new intrusion detection framework based on the existing network security knowledge databa-ses. It included data filtering, attack attempt analyzing and threat evaluation engines. The evolving self-organizing map was used to find attacks with same source and multi targets. Time series analysis method was utilized to obtain correlation rules to correlate intrusion events on-line, so the complicated attacks with disperse attack times could be checked. Then the threat evaluation indexes and quantitative threat evaluation formulas for evaluating serves, hosts and local area network were given. The framework is more integrated and has more useful knowledge than existing intrusion detection system (IDS) and easier to find coordinated attacks with lower false positive rate.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133