Case-Based Reasoning for Intrusion Detection Correlation Analysis

Zeng Rugang,Guan Xiaohong,Zan Xin,Zheng Qinghua
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.04.043
2006-01-01
Abstract:The rule-cased reasoning and model-cased reasoning Intrusion Detection Expert Systems(IDES) face difficulties in acquiring and representing the knowledge.When using a Case-Based Reasoning(CBR) approach,knowledge acquisition is basically capturing actual experiences of past cased.In this paper,a new framework and prototype based on case-based reasoning is proposed.We research function module in CBRIDRA,and discuss the solving idea and implementing approach of some critical techniques:defining attack case,attack case's retrieval,managing case,expert knowledge systems.
What problem does this paper attempt to address?