• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (7): 35-37.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • 上一篇    下一篇

应用层异常检测模型

胡志敏1,2,王红纪3   

  1. (1.湘潭大学信息工程学院,湖南 湘潭 411100;2.湖南城建职业技术学院信息工程系,湖南 湘潭 411101;
    3.漯河职业技术学院计算机工程系,河南 漯河 462000)
  • 收稿日期:2010-01-04 修回日期:2010-03-21 出版日期:2010-06-25 发布日期:2010-06-25
  • 通讯作者: 胡志敏 E-mail:xthuzhimin@163.com
  • 作者简介:胡志敏(1977),女,湖南湘潭人,硕士,讲师,研究方向为计算机网络安全和人工智能等;王红纪,讲师,研究方向为计算机网络安全。
  • 基金资助:

    湖南省教育厅资助科研项目(08D030,07D018)

The Model of Application Level Anomaly Detetion

HU Zhimin1,2,WANG Hongji3   

  1. (1.School of Information Engineering,Xiangtan University,Xiangtan 411100;
    2.Department of Information Engineering,Hunan Urban Construction College,Xiangtan 411100;
    3.Department of Computer Engineering,Luohe Vocational and Technology College,Luohe 462000,China)
  • Received:2010-01-04 Revised:2010-03-21 Online:2010-06-25 Published:2010-06-25
  • Contact: HU Zhimin E-mail:xthuzhimin@163.com

摘要:

目前的应用层异常检测方法多是针对某一种应用层攻击而设计的,通用性较差。本文基于人体免疫系统T细胞识别自体和非自体的原理,设计了基于否定选择的应用层异常检测通用模型,研究了实现否定选择应用层的关键技术。仿真实验表明,该模型能够有效地检测网络服务器的应用层的异常访问,具有广泛的应用前景和推广价值。

关键词: 网络攻击, 应用层异常检测模型, 免疫系统, 否定选择算法, 自体, 非自体

Abstract:

The current technique of application level anomaly detection has a bad universal property which is for one type of application level attack.Inspired from the principle of immune cell identifying nonself,a generic model of application level anomaly detection based on negative selection is designed,and the key technologies of implementation are studied.Simulation tests show that the model can detect the application level anomaly of network servers,and has the advantages of good performance,and broad application prospect.

Key words: network attack;application level anomaly detection model;immune system;negative selected algorithm;self;nonself