首页> 外国专利> METHOD AND DEVICE FOR AUTOMATICALLY ESTABLISHING INTRUSION DETECTION MODEL BASED ON INDUSTRIAL CONTROL NETWORK

METHOD AND DEVICE FOR AUTOMATICALLY ESTABLISHING INTRUSION DETECTION MODEL BASED ON INDUSTRIAL CONTROL NETWORK

机译:基于工业控制网络自动建立入侵检测模型的方法和装置

摘要

The present application discloses a method for automatically establishing an intrusion detection model based on an industrial control network, including: judging whether a first intrusion detection model meets preset detection requirements, and extracting communication behavior traffic data in real time if not; setting a training data set and a test date set according to the communication behavior traffic data; establishing an initial intrusion detection model according to the training data set; and testing the initial intrusion detection model using the test date set, and establishing a second intrusion detection model meeting the preset detection requirements according to the test result. The second intrusion detection model has high detection accuracy, thereby increasing intrusion detection rate of abnormal behavior and reducing false positive rate and false negative rate.
机译:本申请公开了一种基于工业控制网络的自动建立入侵检测模型的方法,包括:判断第一入侵检测模型是否满足预设的检测要求,如果不满足,则实时提取通信行为流量数据;根据通信行为流量数据设置训练数据集和测试日期集;根据训练数据集建立初始入侵检测模型;使用测试日期集测试初始入侵检测模型,并根据测试结果建立满足预设检测要求的第二入侵检测模型。第二入侵检测模型具有较高的检测精度,从而提高了异常行为的入侵检测率,降低了误报率和误报率。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号