首页> 外国专利> Generalized likelihood ratio test (GLRT) based network intrusion detection system in wavelet domain

Generalized likelihood ratio test (GLRT) based network intrusion detection system in wavelet domain

机译:基于小波域的广义似然比测试(GLRT)网络入侵检测系统

摘要

An improved system and method for detecting network anomalies comprises, in one implementation, a computer device and a network anomaly detector module executed by the computer device arranged to electronically sniff network traffic data in an aggregate level using a windowing approach. The windowing approach is configured to view the network traffic data through a plurality of time windows each of which represents a sequence of a feature including packet per second or flow per second. The network anomaly detector module is configured to execute a wavelet transform for capturing properties of the network traffic data, such as long-range dependence and self-similarity. The wavelet transform is a multiresolution transform, and can be configured to decompose and simplify statistics of the network traffic data into a simplified and fast algorithm. The network anomaly detector module is also configured to execute a bivariate Cauchy-Gaussian mixture (BCGM) statistical model for processing and modeling the network traffic data in the wavelet domain. The BCGM statistical model is an approximation of α-stable model, and offers a closed-form expression for probability density function to increase accuracy and analytical tractability, and to facilitate parameter estimations when compared to the α-stable model. Finally, the network anomaly detector module is further configured to execute a generalized likelihood ratio test for detecting the network anomalies.
机译:用于检测网络异常的改进系统和方法包括在一个实现中,计算机设备和由计算机设备执行的网络异常检测器模块,该计算机设备被布置为使用窗口方法在聚合电平中以电子嗅探网络流量数据。窗口方法被配置为通过多个时间窗口查看网络流量数据,每个时间窗口表示包括每秒或每秒流的分组的特征的序列。网络异常检测器模块被配置为执行用于捕获网络流量数据的属性的小波变换,例如远程依赖性和自相似性。小波变换是一种多分辨率变换,并且可以被配置为分解和简化网络流量数据的统计数据,以简化和快速的算法。网络异常检测器模块还被配置为执行双变型Cauchy-Gaussian混合物(BCGM)统计模型,用于处理和建模小波域中的网络流量数据。 BCGM统计模型是α-稳定模型的近似,并且为概率密度函数提供闭合形式的表达,以提高精度和分析途径,并促进与α稳定模型相比的参数估计。最后,网络异常检测器模块还被配置为执行用于检测网络异常的广义似然比测试。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号