吉林大学学报(理学版) ›› 2020, Vol. 58 ›› Issue (2): 321-328.

• 计算机科学 • 上一篇    下一篇

网络入侵中的模糊区域判断算法

黄熙岱   

  1. 广东海洋大学 数学与计算机学院, 广东 湛江 524088
  • 收稿日期:2018-11-21 出版日期:2020-03-26 发布日期:2020-03-25
  • 通讯作者: 黄熙岱 E-mail:hxdai88@163.com

Fuzzy Region Judgment Algorithm in Network Intrusion

HUANG Xidai   

  1. Faculty of Mathematics and Computer Science, Guangdong Ocean University, Zhanjiang 524088, Guangdong Province, China
  • Received:2018-11-21 Online:2020-03-26 Published:2020-03-25
  • Contact: HUANG Xidai E-mail:hxdai88@163.com

摘要: 针对当前网络入侵中模糊区域判断算法未考虑算法的自适应及容错性, 判断效率和稳定性均较差的问题, 提出一种基于多层逻辑结构
的网络入侵中模糊区域判断算法. 首先采用基于多层逻辑结构的模糊区域判断算法, 以自适应和容错性作为约束条件, 通过求取算法不同层反馈解, 得到网络入侵中的模糊区域判断结果; 然后基于判断结果, 采用警报合成算法将较多雷同警报合成为一条警报, 以防止形成警报洪流, 获取最佳模糊区域判断结果. 实验结果表明, 该算法的检测率和误报率总平均值分别为9313%和097%, 平均时间为10.13 s, 表明该算法具有显著的网络入侵模糊区域判断优越性.

关键词: 网络入侵, 模糊区域, 判断, 多层逻辑结构, 警报合成, 警报洪流

Abstract: Aiming at the problem that the current fuzzy region judgment algorithm in network intrusion did not consider the selfadaption and faulttolerance of the algorithm, and had the disadvantage of poor judgment efficiency and stability, the author proposed a fuzzy region judgment algorithm in network intrusion based on multilayer logic structure. Firstly, 
the fuzzy region judgment algorithm based on multilayer logic structure was adopted,  the selfadaption and faulttolerance were taken as constraints, and the fuzzy region judgment results in network intrusion were obtained by calculating the feedback solutions of different layers of the algorithm. Secondly, based on the judgment results, the alarm synthesis algorithm was used to synthesize many identical alarms into an alarm to prevent the formation of alarm flood and obtain the best fuzzy region judgment results. The experimental results show that the total average detection rate and false alarm rate of the proposed algorithm are 9313% and 097% respectively, and the average time is 1013 s, which shows that the proposed algorithm has remarkable advantages in judging the fuzzy area of network intrusion.

Key words: network intrusion, fuzzy area, judgement, multilayer logic structure, alarm synthesis, alarm flood

中图分类号: 

  • TP221.17