首页|增量式入侵检测研究综述

增量式入侵检测研究综述

扫码查看
入侵检测系统可以实时监测网络安全情况并及时发现攻击行为,是网络防御体系重要的组成部分.然而,传统入侵检测系统面向静态网络,难以应对层出不穷的新型攻击手段.部分研究者开始探索如何使入侵检测具备增量学习能力,使其可以针对新攻击类型快速更新已有模型,无需耗费大量资源重新训练即可学习新的知识,以适应纷繁复杂的网络环境.文章梳理了近年来增量式入侵检测相关研究,首先介绍增量学习和入侵检测的基本概念,总结相关领域内常用的数据集,然后对已有方法进行归纳和分析,最后针对现有研究成果存在的问题进行分析,并展望该领域未来的发展趋势.
A Review of Incremental Intrusion Detection
Intrusion detection system is an important component of network defense framework which can monitor the network security situation and detect attacks in real time. However,the traditional intrusion detection systems are oriented to static networks,and it is hard to deal with new attack methods which are coming in all the time. Some researchers have begun to explore how to enable intrusion detection to have incremental capabilities,so that it can quickly update existing models for new types of attacks and learn new knowledge without consuming a lot of resources for retrain,in order to adapt to the complex network environment. This paper aims to summarize the recent research on incremental intrusion detection. Firstly,this paper introduced the basic concepts of incremental learning and intrusion detection,summarized commonly used datasets. Then this paper analyzed existing methods. Finally,this paper analyzed the problems existing in research results,and looked forward to the future development trends in this field.

intrusion detectionincremental learningcontinual learningcyber security

金志刚、陈旭阳、武晓栋、刘凯

展开 >

天津大学电气自动化与信息工程学院,天津 300072

入侵检测 增量学习 持续学习 网络安全

2024

信息网络安全
公安部第三研究所 中国计算机学会计算机安全专业委员会

信息网络安全

CSTPCDCHSSCD北大核心
影响因子:0.814
ISSN:1671-1122
年,卷(期):2024.(12)