详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
     本文针对手机病毒入侵检测的应用要求,在学习和改进前人研究成果的基础上提出了“基于异常数据学习的增量层次聚类算法”(The incremental hierarchical clustering algorithm based on learning abnormal data)简称ICLAD。该算法能很好的解决手机病毒检测应用需求,并以该算法的思想指导设计和开发了针对手机病毒的入侵检测系统,系统部署在移动通信系统的核心网侧,系统通过对网络中获得的海量手机通信数据进行建模学习,从中得到正常和病毒数据特征库,再利用这些属性特征库对网络数据进行检测,以发现异常数据,来给用户提供一个安全可靠的通信环境。系统测试结果表明:该系统能有效的从无类标号的数据中得出规则,利用该规则对数据测试能达到较好的检测目的。
With the development of ICT and the applications of user demand, mobile phones turns can from the traditional "da ge da" as only receive calls gradually to intelligent direction. Smart phone supports a separate operating system, where the system can install and use third-party software, make the phone a change t hat can only provide simple voice and text message service before, starting with integrated short-range wireless transmission, multimedia messaging, mobile Internet, mobile office, audio and video entertainment and simple image processing functions, to become a mobile PC. With the user enjoying a lot easier and fun of life bridged by Intelligent, the viruses and vandalism for smart phones is also increasing, which caused great negative impact to the user's communication security and user experience. The anti-virus technology is lagging behind mobile phone in the virus updates, so we urgently need anti-virus computer experience and accumulation of anti-virus used in the field of mobile phones based on this. The research and implementation against intrusion detection technology of mobile phone viruses is put forward.
     This paper describes the characteristics and operation principle of mobile phone viruses in detail and analysis feasibility of the clustering algorithm in the application of intrusion detection. Then proposing incremental hierarchical clustering algorithm based on Study of abnormal incremental data the characteristics of the virus, which is a cohesive hierarchical clustering algorithm, using the designated representative point of each cluster to represent the actual data. It uses a shrinkage factor to control the data distribution of representative points at the same time. This method is effective to represent irregular data distributions, and have a good adaptability to anomaly point data at the same time. The innovation of this algorithm is that it is able to use incremental abnormal data to correction modeling data on the pre-cluster, So that the algorithm has the ability of self-learning. It will add the latest virus signature data to the virus signature database, based on the effective using of pre-modeling results. This approach is also effective to solve the shortcoming of that once all step has been done, he data in the clustering of clusters can't be changed.
     This article designed and developed intrusion detection system against mobile phone viruses according to "based on abnormal data studying Incremental hierarchical clustering algorithm" and the characteristics of mobile phone virus. System models vast amounts of data obtained through the network, get the normal virus signature data, and then detect the network data using these signatures. System test results show that:the system can effectively derive rules from classless data, achieve better detection purposes by testing using the rules.
    [2]腾讯科技.报告称2009年智能手机市场份额将达17%. [EB/OL]. [2010.03.10].http://tech.qq.com/a/20090130/000029.htm
    [3]赛迪网.2011年第二季度全球智能手机出货量的报告[EB/OL].[2011.12.02]. http://www.ccidreport.com/report/content/7/201172/268669.html
    [4]360安全中心.2011年11月手机安全报告.[EB/OL].[2011.12.02]. http://bbs.360.cn/5295927/252176539.html?page=1
    [5]搜狐IT.IDC:2011年Q3全球智能手机出货量同比增长42.6%. [EB/OL]. [2011.11.17] http://it.sohu.com/20111117/n325994936.shtml
    [6]Mobile phones as computing devices:the viruses are coming!. IEEE Pervasive Computing, vol.3, no.4, pp.11-15,2004
    [9]Cong Jin, Xiaoyan Huang, Songlin Jin. Propagation Model Of Mobile Phone Virus Based on Effieieney of Immunization.2008 International Confereneeon Multi Mediaand Information Teehnology,500-502
    [11]Abhijit Bose and Kang G.Shin. On Mobile Viruses Exploiting Messaging and Bluetooth Serviees. SeeureComm,2006
    [12]John E. Dickerson, Jukka Juslin. Fuzzy Intrusion Detection. IEEE IFSA World Congress and 20th NAFIPS International Conference,2001,3:1506-1510
    [13]Hiren Shah, Undercoier. Fuzzy Clustering for Intrusion Detection, the 12th IEEE international Conf.on Fuzzy System,2003,2:1274-1278
    [16]Susan M. Bridges, Rayford B. Vaughn. Fuzzy Data Mining and Genetic Algorithm Applied to Intrusion Detection. The National Information Systems Security Conference,2000, Vol.19:253-267
    [17]Leonid Ponroy. Intrusion detection with unlabeled data using clustering. Proceedings of ACM CSS Workshop on Data Mining Applied to Security(DMSA-2001),2001,12:438-447
    [18]Klaus Julisch. Data mining for intrusion detection. Applications of Data Mining in Computer Security,2002:366-375
    [19]Guha S, Rastogi R, Shim K. CURE:An efficient clustering algorithm for large databases. In:Haas LM, Tiwary A, eds. Proc. of the ACM SIGMOD Int'1 Conf. on Management of Data. New York:ACM Press,1998.73-84.
    [25]Bace R G. Intrusion Detection Macmillan Technical Publishing. Indianapolis. IN 46290 USA,2000
    [28]Denning DE. An Intrusion-Detection Model [J]. IEEE. Transaction on Software Engineering,1987(2),222-232
    [29]DasguPtaD.Immunity-BasedIntrusionDetectionSystem:AGeneralFramework. Proseedings of 22th NISSC,1999
    [30]RyanJ, Lin M J. Intrusion detection with neural networks. Advances in Neural Information Proeessing Systems10,Cambridge, MA:MIT Press,1998
    [33]JiaweiHan, Michelline Kamber. Data Mining Concept and Technology [M]. Beijing:Mechanical Industry Publishing Society,2007
    [34]Kanungo, T., Mount, D., Piatko, C., Silverman, R., Wu, A., "An efficient k-means clustering algorithm:analysis and implementation," IEEE Transactions on Pattern Analysis and Machine Intelligence, Vol.24, No.7,887-892, (2002).
    [35]Tsai, C.A., Lee, T.C., Ho, I.C., Yang, U.C., Chen, C.H., Chen, J.J., "Multi-class clustering and prediction in the analysis of microarray data," Mathematical Biosciences, Vol.193, Issue 1,79-100, (2005)
    [36]A. Curti, and J. Carver, "Intrusion Response Systems:A Survey", Department of Computer Science, Texas A&M University,2000, Tech Report.
    [37]Jiawei Han等著.范明等译.数据挖掘概念与技术.机械工业出版社.2001.8
    [38]刘红岩,陈剑等.数据挖掘中的数据分类算法综述.清华大学学报:自然科学版2002 Vol.42,P6
    [39]Huang Z. Extensions to the k-means algorithm for clustering large data sets with categorical values. Data Mining and Knowledge,Discovery II,1998,(2):283 304.
    [40]Chaturvedi AD, Green PE, Carroll JD. K-modes clustering. Journal of Classification,2001,18(1):35-56.
    [41]Ma WM, Chow E, Tommy WS. A new shifting grid clustering algorithm. Pattern Recognition,2004,37(3):503-514.
    [42]Pilevar AH, Sukumar M. GCHL:A grid-clustering algorithm for high-dimensional very large spatial data bases. Pattern Recognition Letters, 2005,26(7):9991010.
    [43]Birant D, Kut A. ST-DBSCAN:An algorithm for clustering spatial-temporal data. Data & Knowledge Engineering,2007,60(1):208221
    [46]PortnoyL, Eskin E, Stolfo S. Intrusion detectionwith unlabeled data using clustering [C]//Proceedings ofACMCSSWorkshop on DataMining Applied to Security. Phladelphia:[s. n.],2001
    [49]冯兴杰,黄亚楼增量式CURE聚类算法研究小型微型计算机系统第25卷第10期1847-1849 2004
    [50]The UCIKDD Archive. KDD99 cup dataset [EB/OL].[2011-10-10]. http://kdd. ics. uc. i edu/databas-es/kddcup99/kddcup99. Html

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700