本文介绍入侵检测系统AHIDS,检测基于规则的入侵行为,还具有部分异常检测特点.在AHIDS中采用Agent技术,使其具有层次结构,在网络中实现灵活部署,可以发现入侵者在网络中的异常活动.
论述了数据挖掘和遗传算法在入侵检测中的应用,详细描述了模糊关联规则和模糊频繁序列挖掘,并进一步介绍了如何采用遗传算法优化模糊集合隶属函数,从而达到改善入侵检测系统性能的目的.
In this paper,we present a novel and e fficient algo-rithm -WeiSC for clustering categorical data,it not only be ac-curate but also deserves good scalab ility.Through inference and experience,we show WeiSC be reasonable and efficient.It can be used in network intrusion detection to determine the operations' category.
An efficient method based on data mining is presented for detecting network intrusion. According to this method, user's behavior patterns are mined from IP packets, and used to build user's behavior rules base automatically. By comparing similarity, the new method can be used to detect known and unknown network attacks in real-time. The user's behavior patterns mining algorithm IDSPADE is described in detail, which is the most important part of DMIDS. The experimental results indicate that this algorithm is efficient enough to meet the needs of active detect novel intrusion. Compared with most existing systems by using the pure knowledge engineering approaches, the algorithm is more intelligent and adaptive.
数字商品,即以数字方式存在的商品,主要有正文、图像、视频和音频等4种形式.在Internet电子商务环境下,数字商品很容易被非法复制和扩散,这无疑会妨碍电子商务的健康发展.本文试图解决电子商务环境下数字正文的非法复制和扩散问题.文中首先提出了一种数字正文的多层次、多粒度表示方法;然后,在此基础上给出了相应的重叠性度量算法.该方法不但能较为准确地检测等价复制、超集复制和移位整体复制这样的数字正文整体非法复制行为,而且还能检测诸如子集复制和移位局部复制等部分非法复制行为.同时,该算法也具有较强的扩展性.文章从5个不同的方面对提出的方法进行了测试,实验结果表明该算法是有效的.
利用Markov状态机形式化地描述了一种多级的、基于模式转换的安全系统模型,该模型利用系统可分性构筑,将一个多级的安全系统划分成多个运行模式,利用该模型可提高所设计系统的灵活性,但该模型存在隐通道问题.利用香农信息论和广义图灵测试模型证明该模型中隐通道流量存在上限并给出定量分析,从而为达到可控的系统安全性和灵活性平衡提供了理论基础.采用该系统模型和隐通道流量分析,通过限制模式转换频率和限制参与转换的资源数目等方法可控制隐通道隐患.
颜色直方图计算简单快捷,对大小、方向、物体移动和视点等不敏感而在基于内容的图像检索中得到了广泛的应用.然而,由于它只包含颜色的总体信息而没有反映其相对位置,检索精度受到了一定的限制.针对这个问题,提出了一种颜色-位置直方图,该直方图在不失传统直方图鲁棒性的前提下,将颜色和位置信息有机地融合起来,同时考虑它们对图像内容的表征作用.由于该直方图在反映颜色频率的同时也记录其分段虚拟边界的位置信息,因而较好地解决了传统直方图存在的问题.对合成图像和实际图像所做的实验结果表明,该方法是有效的,具有一定的实用价值.
In this paper we present an overview of data warehouse conceptual model, data organization, metadata, and data marts.We .also give some promising research issues
In this paper we present an intrusion detection system model with the functions of self-learning and self-completing, which can detect the known and novel intrusion activities. In this model, the mobile agent gathers the data collected by the active detection agents and sends it to the event sequence generator. The later preprocess the data and commit the event sequences to data mining engine in order to form the evidence. The detection engine assesses the degree of similarity between the evidence and the rules in rule-lib, then the decision-making engine makes the final adjudication, it also maintains the rule-lib and sends instructions to all active detection agents to deal with various intrusions.
文章从软件工程方法、软件质量国际标准体系、软件可靠性和软件构件技术等方面介绍了现有的软件质量保障技术,同时分析了用数据挖掘方法研究软件质量的可行性,并提出了具体的解决方案.
入侵检测技术是一种主动保护网络资源免受黑客攻击的安全技术.入侵检测系统监控受保护系统的使用情况,发现不安全状态.它不仅帮助系统对付外来网络攻击,还可以查知内部合法用户的非法操作,扩展了系统管理员的安全管理能力.入侵检测为系统提供了实时保护,被认为是防火墙之后的第二道安全闸门.文章讲述了入侵检测技术的发展状况和关键技术,对现有系统进行了分类,并指出了该技术面临的一些挑战.最后提出了一种基于数据挖掘技术的具有自学习、自完善功能的入侵检测模型,可发现已知和未知的滥用入侵和异常入侵活动.
Qinbao Song (宋擒豹)合作论文数Faculty of Electronic and Information Engineering, Xi'an Jiaotong University8