计算机应用 ›› 2012, Vol. 32 ›› Issue (06): 1632-1635.DOI: 10.3724/SP.J.1087.2012.01632

• 信息安全 • 上一篇    下一篇

基于支持向量机和贝叶斯分类的异常检测模型

全亮亮1,吴卫东2   

  1. 1. 武汉科技大学
    2. 武汉科技大学 计算机科学与技术学院, 武汉 430065
  • 收稿日期:2011-11-17 修回日期:2012-01-19 发布日期:2012-06-04 出版日期:2012-06-01
  • 通讯作者: 全亮亮
  • 作者简介:全亮亮(1987-),男,湖北荆门人,硕士研究生,主要研究方向:入侵检测;〓吴卫东(1964-),男,湖北武汉人,副教授,博士,主要研究方向:入侵检测、路由器体系结构、网络测量与分析、路由算法设计。

Anomaly detection model based on support vector machine and Bayesian classification

WU Wei-dong2   

  • Received:2011-11-17 Revised:2012-01-19 Online:2012-06-04 Published:2012-06-01

摘要: 通过对网络攻击类型和入侵检测方法的研究,发现常用的入侵检测方法不能很好地检测U2R和R2L两类攻击。为解决异常检测中对于U2R和R2L两类攻击检测率低的问题,提出了一种基于支持向量机和贝叶斯分类的异常检测模型,该模型利用BIRCH聚类算法减少训练数据集中重复记录,并利用支持向量机分类算法和贝叶斯分类算法分别检测DoS、Probe攻击和U2R、R2L攻击。实验结果表明,该模型对于U2R和R2L的检测率分别提高到了68.6%和45.7%。

关键词: 异常检测, BIRCH聚类, 支持向量机, 贝叶斯分类, KDD99

Abstract: Through the research for the type of network attack and the intrusion detection method,the fact that the normal intrusion detection method is not good enough for detecting U2R and R2L was found. To improve the detection rate of anomaly detection system for U2R and R2L, an anomaly detection model based on support vector machines and Bayesian classifying was suggested. In order to reduce the redundant records in the training data , the BIRCH clustering algorithm is used, besides, the detection model applys SVM for detecting DoS and Probe and uses Bayesian classifying to detect U2R and R2L. Experimental results show that the proposed model can improve obviously detection rate for U2R and R2L.

Key words: Anomaly Detection, BIRCH, SVM, Bayesian, KDD99

中图分类号: