Network intrusion detection method based on Plackett-Luce model

A network intrusion detection and model technology, applied in the field of network security, can solve the problems that intrusion results cannot accurately reflect whether user behavior is abnormal, network traffic data is not comparable, etc.

Pending Publication Date: 2020-09-22
中博信息技术研究院有限公司
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0008] The traditional method judges whether there is a network intrusion based on the user's network traffic. Most of the methods are directly calculated through the user's network traffic data. However, due to the different personal b

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Network intrusion detection method based on Plackett-Luce model
  • Network intrusion detection method based on Plackett-Luce model
  • Network intrusion detection method based on Plackett-Luce model

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0063] like figure 1 A network intrusion detection method based on the Plackett-Luce model shown includes the following steps:

[0064] Step 1: Establish a traffic monitoring server, a statistics server, a function construction server and an observation weight calculation server, and the traffic monitoring server, a statistics server, a function construction server and an observation weight calculation server communicate with each other through the Internet;

[0065] The traffic monitoring server is used to monitor and record the network traffic value used by users every day;

[0066] Step 2: The statistical server retrieves the daily network traffic value used by the user from the traffic monitoring server;

[0067] Establish a user network traffic preference table according to the size of the network traffic value, the network traffic preference table is used to represent the user's preference relationship for the network traffic value, and the preference relationship is st...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a network intrusion detection method based on a Plackett-Luce model,belonging to the technical field of network security. The method comprises the following steps: generating network traffic data in a network according to users; obtaining preference values of a user for network traffic at different times by utilizing a Packett-Luce model; determining the preference relationship of the user to different network flows and the network flow domination times according to the preference value; then, according to a logarithm likelihood function of a Plackett-Luce model, obtaining a logarithm likelihood function of the Plackett-Luce model; constructing an iterative function by using a maximum likelihood estimation method; and finally, standardizing the domination times of the network traffic and substituting into an iterative function to calculate the observation weight of the network traffic each time, andtaking the result as a detection result to detect the network flow.The technical problem that whether the network flow of the user is abnormal or not is judged by adopting the Plackett-Luce model on the basis of the network flow data of the user is solved, inconsistency of behavior habits of different users is fully considered, and whether an intrusion behavior exists in the network or not can be better judged.

Description

technical field [0001] The invention belongs to the technical field of network security, and relates to a network intrusion detection method based on the Plackett-Luce model. Background technique [0002] Intrusion detection refers to starting from some key information points in the network or computer system, searching for relevant information, and conducting in-depth research and analysis on the information. It is a security technology that advances the intrusion attack traces in advance to find out whether there is a violation of the security policy in the computer system or network through comparison detection. Discover network intrusion attacks. [0003] There are mainly four types of intrusion detection technologies: statistical-based anomaly detection technology, predictive model-based anomaly detection technology, neural network-based intrusion detection technology, and data mining-based intrusion detection technology. [0004] Statistical-based anomaly detection t...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): H04L29/06H04L12/24
CPCH04L63/1425H04L41/142
Inventor 张继康王定军费春勇孔伟黄峰
Owner 中博信息技术研究院有限公司
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products