|
With the continuous development of network technology and the increasing popularity of the Internet , computer network security issues have become increasingly prominent, and a variety of intrusion tools and application environment makes the network more vulnerable , increasing threats . Faced with a complex network environment in a variety of security events , firewall, intrusion detection systems and other network security devices every moment will produce a large number of alarms , how these alarms , found valuable information and the potential to become a significant threat of attack issue. In this paper, various alarm a huge number of features , the introduction of fuzzy set theory, for a certain period of time , all the alarming number of occurrences of a fuzzy set is divided , and through data mining techniques in the fuzzy association rule mining discover potential attack . This paper first introduces the relevant background data mining , as well as associated with this article which association rules , analyze the classical Apriori algorithm and its performance shortcomings. Secondly, this paper analyzes the traditional association rules only for Boolean data limitations. For more quantitative data , the introduction of fuzzy set theory and applied quantitative association rule mining fuzzy association rules . Then , this paper presents a fuzzy matrix fuzzy association rule mining algorithm , compared to the traditional algorithm , the performance has made some improvements. Finally, this paper focuses on the fuzzy association rule mining algorithm in the security event correlation application , according to the characteristics of alarm generation , the algorithm is further improved by adding a time window attributes, and have some time to dig through the longest sequence fuzzy frequent alarms attribute set , discover attack steps. Through the MIT Lincoln Laboratory Darpa2000 DDOS1.0 test data sets , the proposed scheme has achieved good results.
|