论文部分内容阅读
在结合了入侵检测系统和犯罪取证系统的基础上,提出了一种基于数据挖掘的入侵检测取证系统。当遭受入侵时,即起到防护作用,同时又实时地收集证据。数据挖掘技术分别应用于入侵检测部分和取证部分,使得检测模型的生成、分发自动化、智能化,提高了检测效率;使得取证系统数据分析速度得到了提高。
Based on the combination of intrusion detection system and crime forensics system, a data mining based intrusion detection forensics system is proposed. When invaded, it serves as a protective and collects evidence in real time. Data mining techniques are applied to intrusion detection and forensics, respectively, which makes the generation and distribution of detection models automatic and intelligent, and improves the detection efficiency. As a result, the data analysis speed of forensics system is improved.