Real-time intrusion detection method based on data mining

A technology of intrusion detection and data mining, applied in the direction of electrical digital data processing, special data processing applications, instruments, etc., can solve the problem of incomplete and inaccurate expert knowledge, difficult to modify or merge with new detection models, and lack of detection of attack methods Ability and other issues

CN102521378AInactive Publication Date: 2012-06-27NANJING UNIV OF POSTS & TELECOMM
0 Cites 10 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2012-06-27
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention relates to a real-time intrusion detection method based on data mining. An ASM (adaptive strategy management) module and an AMM (adaptive model management) module are added into a distributed real-time system framework and used for automatically generating and distributing detection strategies and detection models of an intrusion detection system based on data mining respectively. By the aid of the structure, the problems in terms of automation of related data, automatic generation and distribution of the detection models and the detection strategies, and real-time data evaluation can be solved. A distributed system comprises some components which can be flexibly changed in the system framework to adapt to different environmental changes and meet the demands of users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present invention is a technical solution for intrusion detection. It mainly applies data mining technology to real -time invasion detection applications, which belongs to the field of computer network security technology. Background technique

[0002] With the rapid development of information technology, the risk and opportunities of network invasion have also increased sharply. Design security measures to prevent the resources and data or malicious attacks of unauthorized access system resources and malicious attacks, which has become a very in the current field of cyber security.Important and urgent issues.As an important support technology for information security, the invasion testing technology has developed significantly, and has become an important part of the structure of the security protection system.

[0003] Invasion testing refers to the process of discovering and identifying unauthorized interviews or malicious attacks and invasion in a s...

Examples

Embodiment Construction

[0038] figure 1 is an architecture of the present invention which includes sensors, detectors, a data warehouse, data analysis engine, adaptive policy manager and adaptive pattern manager. The system adopts a distributed architecture and consists of a series of automation components. The components here are independent in design, but can be centrally managed through the data warehouse. Components access each other through a public protocol, where the public protocol uses Extensible Markup Language (XML).

[0039] The basic working relationship between various components such as figure 2 shown.

[0040] Below is the main workflow of the present invention:

[0041] The sensor collects and formats information from the system environment or network environment, and then sends it to the data warehouse for storage. The data analysis engine extracts information from the data warehouse in real time, uses the marking tool to mark the data, and extracts the features of the marked i...