Network intrude detecting method based on inherent subsequence mode decomposition

Yingying Zhu,Mao Ye,Xin Zhao,Lijuan Li,Xi Meng
2008-01-01
Abstract:The invention discloses a network intrusion detection method which makes decomposition based on an inherent subsequence mode, including the following steps: 1, network data interception and pretreatment are done; 2, the sequence of a normal training set and a suspected sequence respectively go through the inherent sequence pattern mining, wherein, a sequence chart is established for the sequences; a closed path in the sequence chart is located and identified as a candidate sequence for the inherent subsequence mode; the inherent subsequence modes composing each candidate sequence are located according to the original sequence; 3, stratification is made in accordance with the support degree; 4, anomaly detection is done as follows: firstly, the inherent subsequence modes of the suspected sequence and the normal sequence respectively and independently form a plurality of layers in accordance with the respective support degree, then the inherent subsequence mode of the suspended sequence and the normal subsequence are matched in the corresponding layer, finally, the anomaly degree is calculated based on the number of matches so as to judge whether the suspected sequence is abnormal. The method overcomes the deficiencies in the prior art and can accurately and effectively identify the existing attacks and the increasing number of new attacks.
What problem does this paper attempt to address?