ADMIDS: A new type of IDS based on agent data-mining
被引:0
|
作者:
Lee, Y
论文数: 0引用数: 0
h-index: 0
机构:
SE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R ChinaSE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R China
Lee, Y
[1
]
Wang, W
论文数: 0引用数: 0
h-index: 0
机构:
SE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R ChinaSE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R China
Wang, W
[1
]
Luo, JZ
论文数: 0引用数: 0
h-index: 0
机构:
SE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R ChinaSE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R China
Luo, JZ
[1
]
机构:
[1] SE Univ, Dept Comp Sci & Engn, Nanjing 210096, Jiangsu, Peoples R China
来源:
PROGRESS IN SAFETY SCIENCE AND TECHNOLOGY, VOL III, PTS A AND B
|
2002年
/
3卷
关键词:
IDS;
agent;
data mining;
security;
D O I:
暂无
中图分类号:
T [工业技术];
学科分类号:
08 ;
摘要:
As an important security inspection approach of computer system, Intrusion Detection System (IDS) has become an indispensable technology for maintaining network security. This paper put forward a new type of intrusion detection system prototype based on Agent data-mining. This system applies agent-based distributed data collection mechanism, uses data-mining technique to perform preparatory data purge on the original audit records, and then processes the sequent flaw data units by STAT(State Transition Analysis Tool) tool. Compared with traditional IDSs, ADMIDS promotes the capability and precision of intrusion detection effectively and possesses fine expansibility and robust. Thus, it fits to be deployed under the circumstance of large heterogeneous network.