自动化与仪器仪表2024,Issue(1) :52-55.DOI:10.14016/j.cnki.1001-9227.2024.01.052

物联网恶意流量检测下基于改进Apriori算法的关联数据回溯分析

Backtracking analysis of correlated data based on improved Apriori algorithm for malicious traffic detection in the Internetof Things

陈钊渊 吴优 张娜 马超 王国仕 罗林波
自动化与仪器仪表2024,Issue(1) :52-55.DOI:10.14016/j.cnki.1001-9227.2024.01.052

物联网恶意流量检测下基于改进Apriori算法的关联数据回溯分析

Backtracking analysis of correlated data based on improved Apriori algorithm for malicious traffic detection in the Internetof Things

陈钊渊 1吴优 1张娜 1马超 1王国仕 1罗林波1
扫码查看

作者信息

  • 1. 海南电网有限责任公司信息通信分公司,海口 570203
  • 折叠

摘要

针对物联网恶意流量检测及关联数据回溯的重要性,研究利用Apriori算法进行关联规则挖掘,并对Apriori算法的不足进行改进,构建恶意流量检测和关联数据回溯模块.对算法及模块性能进行分析测试,结果表明,当事务库很大时,改进的Apriori算法执行时间明显少于传统的Apriori算法;当事务库数量为1 000个时,前者比后者快30.3 s.随着事务库数量的增大,改进Apriori算法的效率明显优于经典Apriori算法的效率.研究方法构建的系统,具有较高的检测率和较低的误检率,其中远程命令控制具有最高的检测率和最低的误检率,分别为90.60%、5.7%.且可以对部分恶意行为进行关联数据回溯分析.说明研究中的物联网恶意流量检测和关联数据回溯对保护物联网健康发展具有较好的作用.

Abstract

In response to the importance of detecting malicious traffic and backtracking associated data in the Internet of Things,the Apriori algorithm is studied for association rule mining,and the shortcomings of the Apriori algorithm are improved to construct a module for malicious traffic detection and backtracking associated data.The analysis and testing of algorithm and module performance show that when the transaction library is large,the execution time of the improved Apriori algorithm is significantly shorter than that of the traditional Apriori algorithm;When the number of transaction libraries is 1000,the former is 30.3 seconds faster than the latter.As the number of transaction libraries increases,the efficiency of the improved Apriori algorithm is significantly better than that of the classic Apriori algorithm.The system constructed by the research method has a high detection rate and a low false detection rate,with remote command control having the highest detection rate and the lowest false detection rate,which are 90.60%and 5.7%,respec-tively.And it can perform correlation data backtracking analysis on some malicious behaviors.The research on malicious traffic detec-tion and associated data backtracking in the Internet of Things has a good effect on protecting the healthy development of the Internet of Things.

关键词

物联网/恶意流量检测/Apriori算法/关联数据回溯

Key words

internet of things/malicious traffic detection/apriori algorithm/related data backtracking

引用本文复制引用

基金项目

海南电网有限责任公司项目(072900HQ 42190001)

出版年

2024
自动化与仪器仪表
重庆工业自动化仪表研究所,重庆市自动化与仪器仪表学会

自动化与仪器仪表

CSTPCD
影响因子:0.327
ISSN:1001-9227
参考文献量15
段落导航相关论文