首页> 外国专利> AUTOMATIC ESTABLISHING METHOD AND APPARATUS FOR INTRUSION DETECTION MODEL BASED ON INDUSTRIAL CONTROL NETWORK

AUTOMATIC ESTABLISHING METHOD AND APPARATUS FOR INTRUSION DETECTION MODEL BASED ON INDUSTRIAL CONTROL NETWORK

机译:基于工控网络的入侵检测模型自动建立方法及装置

摘要

Disclosed is an automatic establishing method of an intrusion detection model based on an industrial control network, comprising: determining whether a first intrusion detection model meets a preset detection requirement, and if not, extracting communication behavior flow data in real time; setting a training data set and a test data set according to the communication behavior flow data; creating an initial intrusion detection model according to the training data set; and testing the initial intrusion detection model using the test data set, and creating a second intrusion detection model meeting a preset detection requirement according to the test result. The detection precision of the second intrusion detection model is high so that an intrusion detection rate of abnormal behaviors is increased, and a false alarm rate and a missing report rate are reduced.
机译:本发明公开了一种基于工控网络的入侵检测模型的自动建立方法,包括:确定第一入侵检测模型是否满足预设的检测要求,如果不满足,则实时提取通信行为流数据;根据所述通信行为流数据设置训练数据集和测试数据集;根据训练数据集创建初始入侵检测模型;使用测试数据集测试初始入侵检测模型,并根据测试结果创建满足预设检测要求的第二入侵检测模型。第二种入侵检测模型的检测精度高,提高了异常行为的入侵检测率,减少了误报率和漏报率。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号