基于多层剪枝的攻击特征自动提取方法

来源期刊:中南大学学报(自然科学版)2014年第10期

论文作者:刘卫国 文碧望

文章页码:3423 - 3430

关键词:入侵检测;攻击特征自动提取;序列比对;剪枝策略

Key words:intrusion detection; signature automatic generation; sequence alignment; pruning strategy

摘    要:针对现有攻击特征自动提取方法抗噪能力弱和准确性不高的问题,利用多层剪枝策略进行攻击特征自动提取。采用多层次架构使得各层间的序列比对相对独立,在同一时间可进行不同层次的多个双序列比对,从而提高计算效率。双序列比对使用改进的NLA算法,修改其相似度得分函数,对连续空位使用线性罚分,同时鼓励连续字符匹配,并用0代替得分为负的值且遇0时回溯,从而得到最优值。通过剪枝判据和置信区间辨别出噪声序列并保留,再与其他序列比对完成后生成的序列进行比对,进而判断剪枝,得到最终的序列比对结果,从而消除了结果中的部分噪声干扰。研究结果表明:该方法具有良好的抗噪能力,提取的攻击特征准确度更高。

Abstract: Aiming at the fact that current approaches for automatically generating attack signatures have problems in noise-tolerance and the accuracy of attack signatures, an approach based on hierarchically pruning strategy (HPS) was presented. Hierarchical structure made the pair-wise alignment between layers run independently and proceed at the same time to increase computational efficiency. The NLA (normalized local alignment) algorithm used in pair-wise alignment was improved by introducing encouraging function and linear punitory factor to adjust the scoring function, and the function replaced the negative score with the zero value and backtracked when it encountered the zero and thus the optimal value was obtained. The noise sequences were judged by the pruning criterion and confidence interval, and compared with the results of other sequence alignment to eliminate noise interference in the final result. The results show that this approach has better noise-tolerance and generates more accurate signatures.

有色金属在线官网  |   会议  |   在线投稿  |   购买纸书  |   科技图书馆

中南大学出版社 技术支持 版权声明   电话:0731-88830515 88830516   传真:0731-88710482   Email:administrator@cnnmol.com

互联网出版许可证:(署)网出证(京)字第342号   京ICP备17050991号-6      京公网安备11010802042557号