J4

• 计算机科学 • 上一篇    下一篇

基于贝叶斯理论的入侵检测评测方法研究

李瑞雪1,2, 房至一1,2, 戴志明1, 闫友来1, 肖 玮1   

  1. 1.吉林大学 计算机科学与技术学院, 长春 130012;2. 吉林大学 符号计算与知识工程教育部重点实验室, 长春 130012
  • 收稿日期:2007-10-20 修回日期:1900-01-01 出版日期:2008-09-26 发布日期:2008-09-26
  • 通讯作者: 房至一

Research of IDS Evaluation Method Based on Bayesian Theory

LI Ruixue1,2, FANG Zhiyi1,2, DAI Zhiming1, YAN Youlai1, XIAO Wei1   

  1. 1. College of Computer Science and Technology, Jilin University, Changchun 130012, China; 2. Key Laboratory of Symbol Computation and Knowledge Engineer of Ministry of Education, Jilin University, Changchun 130012, China
  • Received:2007-10-20 Revised:1900-01-01 Online:2008-09-26 Published:2008-09-26
  • Contact: FANG Zhiyi

摘要: 提出一种基于贝叶斯理论的入侵检测系统(IDS)评测方 法, 设计并建立了一套较完善的入侵检测系统评测体系. 确立了用于评测IDS的4个重要指标:功能指标、 性能指标、 安全性指标和用户可用性指标. 量化分析了一些主要测试指标, 并利用概率树模拟入侵及检测过程. 结果表明, 该方法能在系统的检测率和误报率间找到最佳的阈值平衡点.

关键词: 网络安全, 入侵检测, 评测, 贝叶斯理论, 概率树, 攻击, 测试环境

Abstract: A fresh IDS evaluation method based on Bayesian theory was proposed, and a more perfect Intrusion Detection System Evaluation System was thus designed and constructed. Meanwhile, the four important indices to evaluate IDS, that is, function index, performance index, security index and user availabilityindex, were established. The specific quantitative analysis about some of the major indices was made, moreover, the process of intrusion and detection was simulated with probability tree. The results show that the presented method can find the optimal balance between the detection rate and false alarm rate of the system.

Key words: network security, intrusion detection, evaluation, Bayesian theory, probability tree, attack, test environment

中图分类号: 

  • TP309