• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2011, Vol. 33 ›› Issue (9): 13-18.

• 论文 • 上一篇    下一篇

一种基于相对距离竞争激活的网络入侵检测算法

梁碧珍,陆月然,杨旭光   

  1. (百色学院数学与计算机信息工程系,广西 百色 533000)
  • 收稿日期:2011-05-20 修回日期:2011-07-26 出版日期:2011-09-25 发布日期:2011-09-25
  • 作者简介:梁碧珍(1965),女,广西玉林人,硕士,副教授,研究方向为数据挖掘、计算机安全。陆月然(1965),男,广西天等人,硕士,副教授,研究方向为计算机网络体系结构。杨旭光(1971),男,江西九江人,讲师,研究方向为模式识别。
  • 基金资助:

    国家自然科学基金资助项目(61063046)

A Network Intrusion Detection Algorithm Based on Relative Distance Competitive Activation

LIANG Bizhen,LU Yueran,YANG Xuguang   

  1. (Department of Mathematics and Computer Information Engineering,Baise University,Baise 533000,China)
  • Received:2011-05-20 Revised:2011-07-26 Online:2011-09-25 Published:2011-09-25

摘要:

本文针对目前网络入侵检测学习算法效率不高的问题,首先提出相对距离的概念,然后构造基于相对距离的竞争激活函数和相似性度量,在此基础上提出一种改进的网络入侵检测算法。该算法的优势在于:(1)相对距离能较好地区分极差较大的列属性值并实现归一化;(2)基于相对距离的竞争激活函数可以处理包含符号属性的数据,不需转换为数值,且计算复杂度较低;(3)算法不需要重置机制。通过对KDD CUP99数据集的实验,验证了在检测精度与其他算法相当的情况下,改进算法学习时间和检测时间显著减少。

关键词: 入侵检测, 竞争激活, 相对距离, 相似性度量

Abstract:

Aiming at the problem of lower efficiency of network intrusion detection learning algorithms at present, a concept called relative distance is proposed in this paper, and then competitive activation and similarity measurement are constructed based on it. On that basis we put forward an improved network intrusion detection algorithm. The advantage of the improved algorithm is: (1) The relative distance can distinguish the terms of column with a large range very well and realize normalization in a lower complexity; (2) Competitive activation of relative distance can process the data which includes the characteristics in a lower computation complexity without converting characters into integers; (3)The algorithm needs no reset. Examination results on the KDD Cup99 sets show that the improved algorithm can reduce the learning time and the testing time significantly while maintaining the accuracy of detection compared to other approaches.

Key words: intrusion detection;competitive activation;relive distance;similarity measurement