Dissertation > Excellent graduate degree dissertation topics show
Study of an Agent-based Distributed Intrusion Detection System Using Data Mining Approaches
Author: HuLiNa
Tutor: XuWenBo
School: Jiangnan University
Course: Applied Computer Technology
Keywords: Intrusion Detection Data Mining Agent Network Security
CLC: TP393.08
Type: Master's thesis
Year: 2007
Downloads: 132
Quote: 0
Read: Download Dissertation
Abstract
|
As a kind of active measure of Information Assurance, Intrusion Detection acts as the effective complement to traditional protection techniques and takes a significant part in security. Along with the highly development of the computer technique and network technique, the extensive adoption of the distributed calculation environment, the great storage and the spread of the high bandwidth transmit technique, traditional intrusion detection system based one computer hasn’t already satisfy the need of the safety. As a result, Distributed Intrusion Detection (DID) has developed into the focus of Intrusion Detection and the whole realm of Network Security.Firstly this text carries on the analysis to the present condition of the network safety and the application of IDS, then analyzed the existing technology and the challenge which faces with emphasis. Then, this text also briefly introduced the data mining technology and the development, advantage and present research situation of DIDS.After the analysis and comparison of advantages and disadvantages of the present intrusion detection technologies, we here present an agent-based distributed intrusion detection model using data mining approaches. This model uses the mixed system structure and divides the network under protects into several Sub- net. It is composed of local ID and Sub- net ID. The function divisions of the components use the reference of CIDF model. It is distributed, intelligent and expandable, and resoles the problems of network traffic bottleneck and a single point of failure effectively.Then we introduced the system design and the concrete realization. This text applies a kind of abnormal detection technology which based three kinds of data mining technology (Cluster, Association rule and Sequential rule) which can accurately capture the actual behavior of network traffic. The decision maker combines the alarm from all the detected agents and makes alarm declaration decision.Finally tested with 2000 DARPA from MIT Lincoln Laboratory, Results of experiments show that our system can detect unknown attacks effectively and increases detection efficiency and decreases the number of False Positives.
|
Related Dissertations
- The Research of Malware Detection Technology Based on Active Mode,TP393.08
- Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
- The Problems and Countermeasures in Respect to Agent Construction of the Project: Guangzhou Asian Games Venues,G812.2
- A Study on Healthcare Product Marketing Based on Data Mining Technology,F426.72
- Gao Zhong-ying academic thought and experience and use of Bufei Decoction treatment of common diseases of the respiratory system drug law,R249.2
- Bing- thick academic thought and clinical experience and empirical studies apply to turtle soups treatment of chronic kidney disease,R249.2
- "Social Agent": between Active and Inactive,D625
- Research and Implementation on Service-Oriented Multi-Agent System Cooperation Mechanism,TP393.09
- The Preparation of Aluminum-Ammonium Cationic Starch and Its Application in Papermaking,TS727
- Research of Communication Mechanism in the Distributed Network Based on Mobile Agent,TP393.02
- The optimal scale of investment of private equity funds,O224
- Preliminary Study on Obstacles Effect of Succession Cropping and Reduction Techniques of Microbial Agents in Flue-cured Tobacco,S572
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- Effect of Flue-cured Tobacco Continuous Cropping on Soil Chemical and Physical Properties and Tobacco Leaf Quality,S572
- Development and Application of Biological Seed Coating Formulation for Soybean,S565.1
- The Application of Different Particle Size Peanut Shell Added by Wetting Agent and Nutrient Solution in Cucumber Nursery,S642.2
- The Research on Localization Algorithm of Wireless Sensor Networks,TN929.5
- The Design and Implementation of Bicluster Data Analyzing Software,TP311.52
- Research on Clustering Algorithm Based on Mutation Particle Swarm Optimization,TP18
- Research on Fuzzy C-Mean Clustering Algorithm Based on Particle Swarm Optimization and Shuffled Frog Leaping Algorithm,TP18
- Research on Clustering Algorithm Based on Genetic Algorithm and Rough Set Theory,TP18
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|