Network Anomalies Detection Using Statistical Technique : A Chi- Square approach

Network Anomalies Detection Using Statistical Technique : A Chi- Square approach
复制标题

使用统计技术检测网络异常:卡方方法

DOI:
--
复制
发表时间:
2012
期刊:
--
影响因子:
--
通讯作者:
M. H. Khan
M. H. Khan
中科院分区:
--
文献类型:
--
作者:
Rahul Rastogi;Z. Khan;M. H. Khan

文献摘要

被引文献

相似文献

入侵检测系统是用来检测可疑活动的防御形式之一。然而,网络日志的庞大规模使得人工日志分析变得棘手。此外,基于模式匹配技术的传统入侵检测方法无法满足手动更新这些模式的更快速度的需求。异常检测用作入侵检测系统的一部分,而入侵检测系统又使用某些数据挖掘技术。数据挖掘技术可以应用于网络数据以检测可能的入侵。应用数据挖掘技术的最重要的一步是从数据中选择适当的特征。本文旨在构建一个能够自动检测已知和未知入侵的入侵检测系统。在数据挖掘框架下,IDS 使用统计算法进行训练,称为卡方统计。本研究使用卡方统计技术展示了这些威胁的计划、实施和分析,以防止这些攻击并建立网络入侵检测系统(NIDS)。该模型用于检测基于异常的网络,以了解这种统计技术在检测入侵方面的有效性。
Intrusion Detection System is used to detect suspicious activities is one form of defense. However, the sheer size of the network logs makes human log analysis intractable. Furthermore, traditional intrusion detection methods based on pattern matching techniques cannot cope with the need for faster speed to manually update those patterns. Anomaly detection is used as a part of the intrusion detection system, which in turn use certain data mining techniques. Data mining techniques can be applied to the network data to detect possible intrusions. The foremost step in application of data mining techniques is the selection of appropriate features from the data. This paper aims to build an Intrusion Detection System that can detect known and unknown intrusion automatically. Under a data mining framework, the IDS are trained with statistical algorithm, named Chi-Square statistics. This study shows the plan, implementation and the analyze of these threats by using a Chi-Square statistic technique, in order to prevent these attacks and to make a Network Intrusion detection system (NIDS). This proposed model is used to detect anomaly-based network to see how effective this statistical technique in detecting intrusions.