研究生(外文):Hui-pao Chou
論文名稱(外文):A clustering-based method for detecting network intrusions with new types
指導教授(外文):Tzu-tsung Wong
外文關鍵詞:outlier detectionintrusion detectionsclustering
With the rapid popularization of the Internet, the computer and network already related to our daily life closely. So the topic of the network security had gradually paid more attention to. However, the types of the network intrusions are changed with each passing day. It will be an important issue to detect the occurrence of new types of intrusions. In traditional, intrusions are detected by classification methods, such as decision trees, Bayesian classifiers, SVMs, and so on. All of the above methods are trained by network data to identify the intrusions that had occurred before. However, the general classification methods cannot detect the intrusions never appeared in the training data. This study proposes a clustering-based method to distinguish intrusion data from normal data first. A clustering method is unsupervised and can group data with similar characteristic into the same cluster. A new type of intrusions generally has significantly different data characteristics, hence it can be detected when it cannot be assigned to any known cluster. According to our experimental results, our clustering-based method has a significant superior performance in identifying new types of intrusions than the CBUID, but its resulting false alarm rate is a little bit higher than the CBUID.
摘 要 I
Abstract II
誌 謝 III
目 錄 IV
圖 目 錄 VI
表 目 錄 VIII
第一章 緒論 1
1.1 研究動機 1
1.2 研究目的 2
1.3 研究流程 3
第二章 文獻回顧 4
2.1 異常偵測 4
2.2 異常偵測的方法 5
2.2.1 以距離為基礎的方法 6
2.2.2 以分配為基礎的方法 7
2.2.3 以密度為基礎的方法 8
2.3 分群演算法 9
2.3.1 分割式分群法 10
2.3.2 階層式分群法 10
2.3.3 以密度為基礎和以格狀為基礎的分群法 11
2.3.4 其它分群演法 11
2.4 網路異常入侵偵測相關方法 12
2.5 網路入侵與攻擊行為 13
2.5.1 PROBE 13
2.5.2 U2R和R2L 13
2.5.3 DoS 14
第三章 研究方法 15
3.1 資料前置處理 16
3.2 資料分群 19
3.2.1 K-means演算法 19
3.2.2 CURE 20
3.2.3 DBSCAN 22
3.3 區分正常與異常群組 25
3.4 新型態異常入侵偵測 26
3.4.1 個別性門檻值設定 26
3.4.2 整體性門檻值設定 27
3.5 效能測試方法 28
第四章 實證研究 29
4.1 識別能力測試 29
4.1.1 K-means測試結果 30
4.1.2 CURE測試結果 31
4.1.3 DBSCAN測試結果 32
4.1.4 小結 33
4.2 新型態識別能力測試 34
4.2.1 K-means測試結果 35
4.2.2 CURE測試結果 37
4.2.3 DBSCAN測試結果 40
4.2.4 小結 43
4.3 實際資料檔測試 43
4.3.1 資料檔說明 43
4.3.2 K-means測試結果 48
4.3.3 CURE測試結果 50
4.3.4 DBSCAN測試結果 53
4.3.5 綜合比較 56
第五章 結論與相關建議 60
參 考 文 獻 62
