Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch nhân tạo cho phát hiệ
Luận án: Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch nhân tạo cho phát hiện xâm nhập mạng. Xem tóm tắt và tải về tại LuanAn.net
Graduate University of Science and Technology
Mathematical foundations for Informatics
Luan An
Luận án tiến sĩ
Năm xuất bản
Số trang
103
Thời gian đọc
16 phút
Lượt xem
0
Lượt tải
0
Phí lưu trữ
40 Point
Tổng quan nhanh
- Chủ đề:
- 1. Hệ miễn dịch nhân tạo trong phát hiện xâm nhập mạng
- Số trang:
- 103 trang
- Trường:
- Graduate University of Science and Technology
- Chuyên ngành:
- Mathematical Foundations for Informatics
- Tác giả:
- Nguyen Van Truong
- Năm:
- 2019
Tóm tắt nội dung luận án
I. Hệ miễn dịch nhân tạo trong phát hiện xâm nhập mạng
Hệ miễn dịch nhân tạo là một lĩnh vực của tính toán tiến hóa. Lĩnh vực này mô phỏng cơ chế hoạt động của hệ miễn dịch sinh học. Các thuật toán miễn dịch nhân tạo mô phỏng khả năng nhận diện và loại bỏ tác nhân lạ. Ứng dụng quan trọng nhất là an ninh mạng và phát hiện xâm nhập. Luận án tập trung cải tiến một số thuật toán miễn dịch nhân tạo. Mục tiêu là nâng cao hiệu quả phát hiện xâm nhập mạng. Hệ miễn dịch nhân tạo phân biệt dữ liệu tự thân và không tự thân. Cơ chế này tạo nên nền tảng cho các hệ phát hiện bất thường. Phần này trình bày tổng quan về hệ miễn dịch sinh học. Phần này cũng giới thiệu mô hình hệ miễn dịch nhân tạo cho IDS. Kiến trúc phát hiện bất thường mạng được phân tích chi tiết.
1.1. Tổng quan về hệ miễn dịch sinh học
Hệ miễn dịch sinh học bảo vệ cơ thể khỏi tác nhân gây bệnh. Hệ thống này nhận diện kháng nguyên và tạo kháng thể. Hai cơ chế chính là miễn dịch tự nhiên và miễn dịch thích ứng. Miễn dịch thích ứng ghi nhớ tác nhân lạ sau lần gặp đầu tiên. Nguyên lý chọn lọc vô tính mô tả quá trình sinh sản tế bào lympho. Nguyên lý này là cơ sở cho nhiều thuật toán miễn dịch nhân tạo.
1.2. Mô hình hệ miễn dịch nhân tạo cho IDS
Hệ miễn dịch nhân tạo mô phỏng cơ chế bảo vệ của cơ thể. Mô hình đa lớp được đề xuất cho hệ phát hiện xâm nhập. Mỗi lớp đảm nhận một chức năng phát hiện riêng. Các thuật toán chọn lọc tiêu cực đóng vai trò phát hiện bất thường. Các đặc trưng quan trọng bao gồm khả năng thích nghi và phân tán. Hệ miễn dịch nhân tạo cung cấp nền tảng học máy và nhận dạng mẫu.
1.3. Phát hiện xâm nhập và bất thường mạng
Hệ phát hiện xâm nhập mạng gồm hai loại chính. Hệ phát hiện dựa trên máy chủ giám sát nhật ký hệ thống. Hệ phát hiện dựa trên mạng giám sát luồng dữ liệu gói tin. Phát hiện bất thường nhận diện hành vi lệch khỏi chuẩn. Phương pháp này phát hiện được các cuộc tấn công mới. An ninh mạng và phát hiện xâm nhập là ứng dụng trọng tâm của luận án.
II. Thuật toán tiêu cực trong phát hiện bất thường mạng
Thuật toán tiêu cực là một kỹ thuật quan trọng của hệ miễn dịch nhân tạo. Thuật toán này mô phỏng quá trình tuyển chọn tế bào T trong tuyến ức. Nguyên lý chính là tạo ra các detector nhận diện mẫu không tự thân. Các detector này không phản ứng với dữ liệu tự thân. Kỹ thuật này phù hợp cho phát hiện bất thường mạng. Dữ liệu bình thường được xem là tập tự thân. Dữ liệu tấn công được xem là tập không tự thân. Thuật toán tiêu cực tạo detector từ mẫu tự thân. Các detector phát hiện bất thường khi khớp với mẫu lạ. Luận án cải tiến thuật toán tiêu cực theo nhiều hướng. Các cải tiến tập trung vào tốc độ và độ chính xác.
2.1. Nguyên lý thuật toán chọn lọc tiêu cực
Thuật toán chọn lọc tiêu cực gồm hai giai đoạn chính. Giai đoạn đầu tạo ra các detector ngẫu nhiên. Giai đoạn sau loại bỏ detector khớp với mẫu tự thân. Detector còn lại nhận diện mẫu không tự thân. Quá trình này mô phỏng tuyển chọn âm tính trong cơ thể. Thuật toán tiêu cực đòi hỏi tập dữ liệu tự thân đầy đủ. Chất lượng detector ảnh hưởng trực tiếp đến hiệu quả phát hiện.
2.2. Thuật toán tiêu cực dựa trên r chunk
Luật khớp r-chunk chia chuỗi thành các đoạn ngắn cố định. Detector r-chunk có độ dài r ký tự. Detector khớp khi có một đoạn r liên tiếp trùng nhau. Luật khớp r-contiguous yêu cầu r ký tự liên tiếp trùng nhau. Hai luật khớp này được sử dụng phổ biến. Luận án đề xuất các cải tiến cho thuật toán dựa trên r-chunk. Các cải tiến giúp tăng tốc quá trình phát hiện.
2.3. Biểu diễn dữ liệu vòng và tập DARPA
Biểu diễn vòng là một cách mô hình hóa chuỗi dữ liệu. Chuỗi được nối hai đầu tạo thành vòng khép kín. Cách biểu diễn này hỗ trợ khớp detector linh hoạt. Tập dữ liệu DARPA-Lincoln được dùng để đánh giá. Tập dữ liệu này chứa lưu lượng mạng chuẩn và tấn công. Dữ liệu giúp kiểm thử độ chính xác của thuật toán tiêu cực. Kết quả thực nghiệm trên DARPA được trình bày trong luận án.
III. Thuật toán chọn lọc vô tính trong miễn dịch nhân tạo
Thuật toán chọn lọc vô tính là một thuật toán quan trọng trong hệ miễn dịch nhân tạo. Thuật toán này mô phỏng quá trình sinh sản vô tính của tế bào lympho. Các cá thể tốt được nhân bản và đột biến để cải thiện chất lượng. Kỹ thuật này giúp tối ưu hóa các bài toán phức tạp. Tối ưu hóa đa mục tiêu giải quyết nhiều hàm mục tiêu cùng lúc. Trong phát hiện xâm nhập, độ chính xác và tỷ lệ cảnh báo giả là hai mục tiêu. Mạng miễn dịch nhân tạo kết nối các kháng thể thành một mạng lưới. Tính toán tiến hóa cung cấp nền tảng chung cho các thuật toán này. Thuật toán di truyền và tối ưu hóa bầy đàn là các phương pháp liên quan. Luận án so sánh và kết hợp các phương pháp để nâng cao hiệu quả.
3.1. Thuật toán chọn lọc vô tính và ứng dụng
Thuật toán chọn lọc vô tính dựa trên ba nguyên lý chính. Nguyên lý thứ nhất là nhân bản các cá thể tốt. Nguyên lý thứ hai là đột biến để tạo đa dạng. Nguyên lý thứ ba là chọn lọc giữ lại cá thể tốt nhất. Thuật toán này phù hợp với bài toán tối ưu. Luận án sử dụng chọn lọc vô tính cho phát hiện xâm nhập mạng. Phương pháp cải thiện độ chính xác của hệ thống.
3.2. Tối ưu hóa đa mục tiêu trong AIS
Tối ưu hóa đa mục tiêu xử lý nhiều tiêu chí xung đột nhau. Mỗi giải pháp được đánh giá theo vector mục tiêu. Khái niệm Pareto tối ưu mô tả tập giải pháp tốt nhất. Trong phát hiện xâm nhập, hai mục tiêu chính được xem xét. Mục tiêu thứ nhất là tỷ lệ phát hiện cao. Mục tiêu thứ hai là tỷ lệ cảnh báo giả thấp. Hệ miễn dịch nhân tạo hỗ trợ giải quyết bài toán đa mục tiêu hiệu quả.
3.3. Tính toán tiến hóa và thuật toán di truyền
Tính toán tiến hóa bao gồm nhiều họ thuật toán khác nhau. Thuật toán di truyền mô phỏng quá trình tiến hóa tự nhiên. Tối ưu hóa bầy đàn mô phỏng hành vi bầy đàn. Hai phương pháp này liên quan chặt chẽ với hệ miễn dịch nhân tạo. Các kỹ thuật tiến hóa được dùng để tối ưu detector. Luận án kết hợp tính toán tiến hóa với miễn dịch nhân tạo. Sự kết hợp mang lại kết quả phát hiện xâm nhập tốt hơn.
IV. Kết hợp thuật toán tiêu cực và dương tính thông minh
Thuật toán chọn lọc dương tính là một kỹ thuật đối lập với thuật toán tiêu cực. Thuật toán dương tính giữ lại các detector khớp với mẫu tự thân. Sự kết hợp hai hướng chọn lọc mang lại hiệu quả cao. Luận án đề xuất thuật toán tiêu cực-dương tính mới. Thuật toán mới kết hợp ưu điểm của cả hai phương pháp. Ngoài ra, luận án nghiên cứu sinh tập detector gọn. Tập detector gọn giảm chi phí lưu trữ và tăng tốc độ. Các thuật toán đề xuất được kiểm chứng bằng thực nghiệm. Kết quả cho thấy hiệu quả phát hiện được cải thiện đáng kể. Phần này trình bày chi tiết các đóng góp chính của luận án.
4.1. Thuật toán chọn lọc dương tính
Thuật toán chọn lọc dương tính mô phỏng tuyển chọn dương trong cơ thể. Detector phản ứng với mẫu tự thân được giữ lại. Detector này nhận diện các mẫu dữ liệu bình thường. Phương pháp phát hiện bất thường dựa trên độ lệch chuẩn. Thuật toán dựa trên r-chunk được phát triển trong luận án. Cây tiền tố được dùng để biểu diễn tập detector hiệu quả.
4.2. Thuật toán tiêu cực dương tính mới
Luận án đề xuất thuật toán kết hợp tiêu cực và dương tính. Thuật toán mới tận dụng lợi thế của cả hai hướng. Thuật toán tiêu cực phát hiện mẫu không tự thân. Thuật toán dương tính xác định chính xác mẫu tự thân. Sự kết hợp giảm thiểu sai sót trong phát hiện xâm nhập. Kết quả thực nghiệm cho thấy độ chính xác cao hơn.
4.3. Sinh tập detector gọn và hiệu quả
Sinh tập detector gọn là một bài toán quan trọng. Tập detector lớn gây tốn bộ nhớ và thời gian. Luận án đề xuất thuật toán sinh detector gọn. Phương pháp sử dụng luật khớp rcbvl. Cây nhị phân biểu diễn tập detector một cách cô đọng. Thuật toán chuyển cây dương tính thành cây âm tính. Kết quả giảm đáng kể số lượng detector cần lưu trữ.
V. Thuật toán nhanh ứng dụng cho an ninh mạng và bảo mật
Luận án phát triển các thuật toán chọn lọc nhanh cho an ninh mạng. Thuật toán tiêu cực nhanh dựa trên detector r-chunk được đề xuất. Thuật toán tiêu cực nhanh dựa trên detector r-contiguous cũng được nghiên cứu. Các thuật toán này giảm thời gian xử lý đáng kể. Hệ miễn dịch nhân tạo lai được ứng dụng cho bảo mật mạng. Phương pháp lai kết hợp chọn lọc dương tính với detector chunk. Hiệu năng được đánh giá bằng các chỉ số cụ thể. Độ chính xác, độ phủ và tốc độ được đo lường. Kết quả thực nghiệm khẳng định hiệu quả của các thuật toán đề xuất. Đóng góp chính góp phần nâng cao an ninh mạng và phát hiện xâm nhập.
5.1. Thuật toán tiêu cực nhanh dựa trên r chunk
Thuật toán tiêu cực truyền thống chậm với dữ liệu lớn. Luận án đề xuất thuật toán nhanh dựa trên detector r-chunk. Phương pháp sử dụng cây tần suất để tổ chức dữ liệu. Cây tần suất biểu diễn toàn bộ detector 3-chunk. Cấu trúc dữ liệu giúp tra cứu nhanh hơn. Thời gian phát hiện được giảm xuống đáng kể.
5.2. Thuật toán tiêu cực nhanh dựa trên r contiguous
Luật khớp r-contiguous yêu cầu các ký tự liên tiếp trùng nhau. Thuật toán nhanh cho luật khớp này cũng được phát triển. Phương pháp tối ưu hóa việc duyệt detector. Kỹ thuật này phù hợp với dữ liệu mạng quy mô lớn. Kết quả cho thấy tốc độ tăng đáng kể so với truyền thống.
5.3. Hệ miễn dịch lai cho bảo mật mạng
Hệ miễn dịch lai kết hợp chọn lọc dương tính và tiêu cực. Thuật toán lai sử dụng detector chunk trong chọn lọc dương tính. Hệ thống phân tích lưu lượng mạng theo thời gian thực. Các chỉ số đánh giá bao gồm tỷ lệ phát hiện và cảnh báo giả. Kết quả thực nghiệm trên dữ liệu DARPA cho kết quả tốt. Hệ thống góp phần bảo vệ an ninh mạng hiệu quả.
Tải xuống file đầy đủ để xem toàn bộ nội dung
Tải đầy đủ (103 trang)Trích đoạn nội dung luận án
Tải xuống để đọc toàn bộMINISTRY OF EDUCATION VIETNAMESE ACADEMY AND TRAINING OF SCIENCE AND TECHNOLOGY GRADUATE UNIVERSITY OF SCIENCE AND TECHNOLOGY ———————————— NGUYEN VAN TRUONG IMPROVING SOME ARTIFICIAL IMMUNE ALGORITHMS FOR NETWORK INTRUSION DETECTION THE THESIS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY IN MATHEMATICS Hanoi - 2019 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com MINISTRY OF EDUCATION VIETNAMESE ACADEMY AND TRAINING OF SCIENCE AND TECHNOLOGY GRADUATE UNIVERSITY OF SCIENCE AND TECHNOLOGY ———————————— NGUYEN VAN TRUONG IMPROVING SOME ARTIFICIAL IMMUNE ALGORITHMS FOR NETWORK INTRUSION DETECTION THE THESIS FOR THE DEGREE OF DOCTOR OF PHILOSOPHY IN MATHEMATICS Major: Mathematical foundations for Informatics Code: 62 46 01 10 Scientific supervisor: 1. Nguyen Xuan Hoai 2. Luong Chi Mai Hanoi - 2019 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com Acknowledgments First of all I would like to thank is my principal supervisor, Assoc. Nguyen Xuan Hoai for introducing me to the field of Artificial Immune System.
He guides me step by step through research activities such as seminar presentations, paper writing, etc. His genius has been a constant source of help. I am intrigued by his constructive criticism throughout my PhD. I wish also to thank my co-supervisor, Assoc.
Luong Chi Mai. She is always very enthusiastic in our discussion promising research questions. It is a pleasure and luxury for me to work with her. This thesis could not have been possible without my supervisors’ support.
I gratefully acknowledge the support from Institute of Information Technology, Vietnamese Academy of Science and Technology, and from Thai Nguyen University of Education. I thank the financial support from the National Foundation for Science and Technology Development (NAFOSTED), ASEAN-European Academic University Network (ASEA-UNINET). Vu Duc Quang, M. Trinh Van Ha and M.
Pham Dinh Lam, my co-authors of published papers. Tran Quang Anh and Dr. Nguyen Quang Uy for many helpful insights for my research. I thank colleagues, especially my cool labmate Mr.
Nguyen Tran Dinh Long, in IT Research & Development Center, HaNoi University. Finally, I thank my family for their endless love and steady support. LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com Certificate of Originality I hereby declare that this submission is my own work under my scientific super- visors, Assoc. Nguyen Xuan Hoai, and Assoc.
Luong Chi Mai. I declare that, it contains no material previously published or written by another person, except where due reference is made in the text of the thesis. In addition, I certify that all my co-authors allow me to present our work in this thesis. student Nguyen Van Truong LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com i Contents List of Figures v List of Tables vii Notation and Abbreviation viii INTRODUCTION 1 Motivation.
2 Outline of thesis .1 Detection of Network Anomalies .1 Host-Based IDS .2 Network-Based IDS .2 A brief overview of human immune system .3 AIS for IDS .1 AIS model for IDS .2 AIS features for IDS .1 Negative Selection Algorithms. 12 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.2 Positive Selection Algorithms .5 Basic terms and definitions .1 Strings, substrings and languages .2 Prefix trees, prefix DAGs and automata .4 Detection in r-chunk detector-based positive selection .7 Ring representation of data .1 The DARPA-Lincoln datasets. 29 2 COMBINATION OF NEGATIVE SELECTION AND POSITIVE SE- LECTION 30 2.3 New Positive-Negative Selection Algorithm. 40 3 GENERATION OF COMPACT DETECTOR SET 43 3.3 New negative selection algorithm.
45 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.1 Detectors set generation under rcbvl matching rule .2 Detection under rcbvl matching rule. 49 4 FAST SELECTION ALGORITHMS 51 4.3 A fast negative selection algorithm based on r-chunk detector .4 A fast negative selection algorithm based on r-contiguous detector. 65 5 APPLYING HYBRID ARTIFICIAL IMMUNE SYSTEM FOR NET- WORK SECURITY 66 5.3 Hybrid positive selection algorithm with chunk detectors .3 Performance metrics and parameters. 76 CONCLUSIONS 78 Contributions of this thesis.
80 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com iv BIBLIOGRAPHY 81 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com v List of Figures 1.1 Classification of anomaly-based intrusion detection methods .2 Multi-layered protection and elimination architecture .3 Multi-layer AIS model for IDS .4 Outline of a typical negative selection algorithm.5 Outline of a typical positive selection algorithm.6 Example of a prefix tree and a prefix DAG.7 Existence of holes.8 Negative selections with 3-chunk and 3-contiguous detectors.9 A simple ring-based representation (b) of a string (a).10 Frequency trees for all 3-chunk detectors.1 Binary tree representation of the detectors set generated from S.2 Conversion of a positive tree to a negative one.3 Diagram of the Detector Generation Algorithm.4 Diagram of the Positive-Negative Selection Algorithm.5 One node is reduced in a tree: a compact positive tree has 4 nodes (a) and its conversion (a negative tree) has 3 node (b).6 Detection time of NSA and PNSA.7 Nodes reduction on trees created by PNSA on Netflow dataset.8 Comparison of nodes reduction on Spambase dataset.1 Diagram of a algorithm to generate perfect rcbvl detectors set.1 Diagram of the algorithm to generate positive r-chunk detectors set. 55 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.2 A prefix DAG G and an automaton M .3 Diagram of the algorithm to generate negative r-contiguous detectors set.4 An automaton represents 3-contiguous detectors set.5 Comparison of ratios of runtime of r-chunk detector-based NSA to run- time of Chunk-NSA .6 Comparison of ratios of runtime of r-contiguous detector-based NSA to runtime of Cont-NSA. 64 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com vii List of Tables 1.1 Performance comparison of NSAs on linear strings and ring strings.1 Comparison of memory and detection time reductions.2 Comparison of nodes generation on Netflow dataset.1 Data and parameters distribution for experiments and results comparison.1 Comparison of our results with the runtimes of previously published algorithms.2 Comparison of Chunk-NSA with r-chunk detector-based NSA.3 Comparison of proposed Cont-NSA with r-contiguous detector-based NSA.1 Features for NIDS.2 Distribution of flows and parameters for experiments.3 Comparison between PSA2 and other algorithms.4 Comparison between ring string-based PSA2 and linear string-based PSA2. 76 LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com viii Notation and Abbreviation Notation ` Length of data samples Sr Set of ring presentations of all strings in S |X| Cardinality of set X Σ An alphabet, a nonempty and finite set of symbols Σk Set of all strings of length k on alphabet Σ, where k is a positive integer.
Σ∗ Set of all strings on alphabet Σ, including an empty string. r Matching threshold Dpi Set of all positive r-chunk detectors at position i. Dni Set of all negative r-chunk detectors at position i. CHUNKp (S, r) Set of all positive r-chunk detectors.
CHUNK(S, r) Set of all negative r-chunk detectors. CONT(S, r) Set of all r-contiguous detectors. L(X) Set of all nonself strings detected by X. rcbvl r-contiguous bit with variable length.
Abbreviation AIS Artificial Immune System ACC Accuracy Rate ACO Ant Colony Optimization ANIDS Anomaly Network Intrusion Detection System BBNN Block-Based Neural Network Chunk-NSA Chunk Detector-Based Negative Selection Algorithm Cont-NSA Contiguous Detector-Based Negative Selection Algorithm DR Detection Rate DAG Directed Acyclic Graph FAR False Alarm Rate GA Genetic Algorithm HIS Human Immune System HIDS Host Intrusion Detection System IDS Intrusion Detection System LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com ix ML Machine Learning MLP Multilayer Perceptron NIDS Network Intrusion Detection System NS Negative Selection NSA Negative Selection Algorithm NSM Negative Selection Mutation PNSA Positive-Negative Selection Algorithm PSA Positive Selection Algorithm PSA2 Two-class Positive Selection Algorithm PSO Particle Swarm Optimization PSOGSA Particle Swarm Optimization-Gravitational Search Algorithm RNSA Real-valued NSA SVM Support Vector Machines TCP Transmission Control Protocol VNSA Variable length detector-based NSA LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com 1 INTRODUCTION Motivation Internet users and computer networks are suffering from rapidly increasing num- ber of attacks. In order to keep them safe, there is a need for effective security monitor- ing systems, such as Intrusion Detection Systems (IDS). However, intrusion detection has to face a number of different problems such as large network traffic volumes, im- balanced data distribution, difficulties to realize decision boundaries between normal and abnormal actions, and a requirement for continuous adaptation to a constantly changing environment. As a result, many researchers have attempted to use different types of approaches to build reliable intrusion detection system.
Computational intelligence techniques, known for their ability to adapt and to exhibit fault tolerance, high computational speed and resilience against noisy informa- tion, are hopefully alternative methods to the problem. One of the promising computational intelligence methods for intrusion detection that have emerged recently are artificial immune systems (AIS) inspired by the biolog- ical immune system. Negative selection algorithm (NSA), a dominating model of AIS, is widely used for intrusion detection systems (IDS) [55, 52]. Despite its successful application, NSA has some weaknesses: 1-High false positive rate (false alarm rate) and false negative rate, 2-High training and testing time, 3-Exponential relationship between the size of the training data and the number of detectors possibly generated for testing, 4-Changeable definitions of ”normal data” and ”abnormal data” in dynamic network environment [55, 79, 92].
To overcome these limitations, trends of recent works are to concentrate on complex structures of immune detectors, matching methods and hybrid NSAs [11, 94, 52]. Following trends mentioned above, in this thesis we investigate the ability of NSA to combine with other classification methods and propose more effective data LUAN VAN CHAT LUONG download : add luanvanchat@agmail.com 2 representations to improve some NSA’s weaknesses. Scientific meaning of the thesis: to provide further background to improve per- formance of AIS-based computer security field in particular and IDS in general. Reality meaning of the thesis: to assist computer security practicers or experts implement their IDS with new features from AIS origin.
The major contributions of this research are: Propose a new representation of data for better performance of IDS; Propose a combination of existing algorithms as well as some statistical approaches in an uniform framework; Propose a complete and non-redundant detector representation to archive optimal time and memory complex- ities. Objectives Since data representation is one of the factors that affect the training and testing time, a compact and complete detector generation algorithm is investigated. The thesis investigates optimal algorithms to generate detector set in AIS. They help to reduce both training time and detecting time of AIS-based IDSs.
Also, it is regarded to propose and investigate an AIS-based IDS that can promptly detect attacks, either if they are known or never seen before. The proposed system makes use of AIS with statistics as analysis methods and flow-based network traffic as experimental data. Problem statements Since the NSA has some limitations as listed in the first section, this thesis concentrates on three problems: 1. The first problem is to find compact representations of data.
Objectives of this problem’s solution is not only to minimize memory storage but also to reduce testing time. The second problem is to propose algorithms that can reduce training time and testing time in compared with all existing related algorithms. LUAN VAN CHAT LUONG download : add luanvanchat@agmail. The third problem is to improve detection performance with respect to reduc- ing false alarm rates while keeping detection rate and accuracy rate as high as possible.
Solutions of these problems can partly improve first three weaknesses as listed in the first section. Regarding to the last NSAs’ weakness about changeable definitions of ”normal data” and ”abnormal data” in dynamic network environment, we consider it as a risk in our proposed algorithm and left it for future work. Logically, it is impossible to find an optimal algorithm that can both reduce time and memory complexities and obtain best detection performance. These aspects are always in conflict with each other.
Thus, in each chapter, we will propose algorithms to solve each problem quite independently. The intrusion detection problem mentioned in this thesis can be informally stated as: Given a finite set S of network flows which labeled with self (normal) or nonself (abnormal).
Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ
Trích dẫn luận án này
Nguyen Van Truong (2019). Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n [Luận án tiến sĩ, Graduate University of Science and Technology]. LuanAn.net. https://luanan.net/tai-lieu-khac/luan-an-tien-si-cai-tien-mot-so-thuat-toan-trong-mien-dich-nhan-tao-cho-phat-hien-xam-nhap-mang
Câu hỏi thường gặp
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" nghiên cứu về vấn đề gì?
Luận án: Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch nhân tạo cho phát hiện xâm nhập mạng. Xem tóm tắt và tải về tại LuanAn.net
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" được bảo vệ tại trường nào?
Luận án này được bảo vệ tại Graduate University of Science and Technology. Năm bảo vệ: 2019.
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" thuộc chuyên ngành gì?
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" thuộc chuyên ngành Mathematical foundations for Informatics. Danh mục: Tài liệu khác.
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" có bao nhiêu trang?
Luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" có 103 trang. Bạn có thể xem trước một phần tài liệu ngay trên trang web trước khi tải về.
Cách tải luận án "Luận án tiến sĩ cải tiến một số thuật toán trong miễn dịch n" về máy như thế nào?
Để tải luận án về máy, bạn nhấn nút "Tải xuống ngay" trên trang này, sau đó hoàn tất thanh toán phí lưu trữ. File sẽ được tải xuống ngay sau khi thanh toán thành công. Hỗ trợ qua Zalo: 0559 297 239.