计算机科学与技术

一种网络入侵检测特征提取方法

展开
  • 华东理工大学 信息科学与工程学院, 上海 200237
张雪芹(1972-),女,博士,副教授,主要从事网络安全、模式识别研究.

收稿日期: 2009-02-25

  修回日期: 2009-04-29

  网络出版日期: 2010-01-25

基金资助

国家自然科学基金资助项目(60773094)

An efficient Network Intrusion Detection Feature Extraction Method

Expand
  •  School of Information Science and Engineering, East China University of Science and Engineering, Shanghai 200237, China
张雪芹(1972-),女,博士,副教授,主要从事网络安全、模式识别研究.

Received date: 2009-02-25

  Revised date: 2009-04-29

  Online published: 2010-01-25

Supported by

国家自然科学基金资助项目(60773094)

摘要

为了去除冗余特征,降低系统存储和运算负担,提高网络入侵检测分类器的性能,文中提出了一种基于Fisher分和支持向量机的网络入侵检测特征提取方法.针对KDD,99网络入侵检测数据集,应用该方法得到了混合攻击和4种单一攻击模式下的特征重要度排序,选取重要特征建立支持向量机入侵检测分类器.结果表明,该分类器精度与使用全部特征构建的支持向量机分类器相当,训练和测试时间则显著降低

本文引用格式

张雪芹 顾春华 . 一种网络入侵检测特征提取方法[J]. 华南理工大学学报(自然科学版), 2010 , 38(1) : 81 -86 . DOI: 10.3969/j.issn.1000-565X.2010.01.016

Abstract

In order to eliminate redundant features, reduce the system burden of storage and computation, and improve the performance of the classifier for network intrusion detection, a method to extract network intrusion detection feature is proposed based on the Fisher score and the support vector machine (SVM). Then, in accordance with KDD,99 network intrusion detection dataset, the feature significance rankings for the mixed attack and four single attacks are respectively obtained by using the proposed method. By extracting important features, a SVM classifier is thus constructed. Experimental results show that, as compared with the classifier constructed based on all features, the new classifier is of approximately equivalent accuracy and dramatically low training and testing time cost.

文章导航

/