信息网络安全 ›› 2016, Vol. 16 ›› Issue (1): 6-10.doi: 10.3969/j.issn.1671-1122.2016.01.002

• • 上一篇    下一篇

一种基于偏最小二乘的网络入侵检测方法分析

陈善雄1(), 彭茂玲2, 彭喜化1   

  1. 1.西南大学计算机与信息科学学院,重庆 400715
    2.重庆城市管理职业技术学院,重庆 401331
  • 收稿日期:2015-10-31 出版日期:2016-01-01 发布日期:2020-05-13
  • 作者简介:

    作者简介: 陈善雄 (1981-),男,重庆, 副教授 ,博士,主要研究方向为网络安全、数据挖掘;彭茂玲(1981-), 女, 重庆,副教授,硕士, 主要研究方向为高性能网络系统、信息安全;彭喜化(1978-), 男 ,重庆 , 讲师 ,硕士,主要研究方向为数据挖掘、模式识别。

  • 基金资助:
    基金项目: 国家自然科学基金[61303227];西南大学博士启动基金[swu1114033];中央高校基本科研业务费[XDJK2014C039、XDJK2016C045]

A Network Intrusion Detection Method Based on Partial Least Squares

Shanxiong CHEN1(), Maoling PENG2, Xihua PENG1   

  1. 1.College of Computer and Information Science, Southwest University, Chongqing 400715, China
    2.Chongqing City Management College, Chongqing 401331, China
  • Received:2015-10-31 Online:2016-01-01 Published:2020-05-13

摘要:

由于网络应用的日益广泛,网络安全在计算机网络中的作用越来越重要。通过对网络数据流的分析和鉴别,进而甄别出入侵行为是网络安全研究的一个重要方向。当网络遭受来自外部的入侵时,入侵数据可以视为叠加在正常网络流量上的一个非线性扰动,其扰动强度受入侵时间、入侵数据流量大小影响。因此我们可以利用非线性理论和模型,建立网络非线性数据的模型,通过参数拟合发现异常数据流。文章在网络入侵检测中引入了非线性回归方法--偏最小二乘,来预测网络行为。同时在偏最小二乘的残差计算中采用了Kullback-Leibler 散度作为迭代计算标准,提升了检测速度和精度。

关键词: 散度, 偏最小二乘, 入侵检测, 网络安全

Abstract:

Due to widely network applications, the role of network security is becoming more and more important in computer networks. The analysis and discrimination of network data stream and intrusion behaviors is an important direction of network security research. When anomelous behavior coming from outside is detected in network, intrusion data can be treat as nonlinear disturbance which is overlay normal network data flow. Strength of disturbance is influenced by the stream of intrusion data. Therefore, we can use non-linear theory and model to construct non-linear pattern for the network data stream. Then abnormal behavior could be discovered based on parameter fitting method. In response to network intrusion detection, this paper introduces a nonlinear regression method - partial least squares to predict the network behaviors. At the same time, in the calculation of partial least squares residuals, the paper adopts the Kullback Leibler-divergence as an iterative calculation standard so as to improve the detection speed and accuracy.

Key words: divergence, partial least squares, intrusion detection, network security

中图分类号: