论文标题
从数据库过程中知识发现的角度来调查网络入侵检测方法
Survey of Network Intrusion Detection Methods from the Perspective of the Knowledge Discovery in Databases Process
论文作者
论文摘要
多年来,针对信息和通信系统的网络攻击一直是研究界的重点。网络入侵检测是一个复杂的问题,提出了各种各样的挑战。目前许多攻击仍未被发现,而由于连接的设备的扩散和通信技术的发展,较新的攻击出现了。在这项调查中,我们回顾了已应用于网络数据的方法,目的是开发入侵检测器,但与该地区先前的评论相反,我们从数据库(KDD)过程中知识发现的角度进行了分析。因此,我们讨论用于捕获,准备和转换数据的技术以及数据挖掘和评估方法。此外,我们还介绍了使用这些技术中每种技术的特征和动机,并根据数据挖掘和KDD领域所使用的术语提出了对入侵检测器的更适当和最新的分类法和定义。遵循的评估程序非常重要,以评估不同的检测器,讨论其在当前实际网络中的适用性。最后,由于这篇文献综述,我们研究了一些开放问题,这些问题需要考虑在网络安全领域进行进一步研究。
The identification of cyberattacks which target information and communication systems has been a focus of the research community for years. Network intrusion detection is a complex problem which presents a diverse number of challenges. Many attacks currently remain undetected, while newer ones emerge due to the proliferation of connected devices and the evolution of communication technology. In this survey, we review the methods that have been applied to network data with the purpose of developing an intrusion detector, but contrary to previous reviews in the area, we analyze them from the perspective of the Knowledge Discovery in Databases (KDD) process. As such, we discuss the techniques used for the capture, preparation and transformation of the data, as well as, the data mining and evaluation methods. In addition, we also present the characteristics and motivations behind the use of each of these techniques and propose more adequate and up-to-date taxonomies and definitions for intrusion detectors based on the terminology used in the area of data mining and KDD. Special importance is given to the evaluation procedures followed to assess the different detectors, discussing their applicability in current real networks. Finally, as a result of this literature review, we investigate some open issues which will need to be considered for further research in the area of network security.