dc.description.abstract網路入侵偵測系統(network intrusion detection System, NIDS)大多數使用負面表列(misuse-detection)來偵測網路入侵行為,此缺點為需預先內建資料庫樣式比對的功能,而網路入侵行為種類繁多,很難全部網羅。而正面表列方式(anomaly-detection)從網路行為實例中來建立入侵偵測的正常門檻值(threshold),優點為可以省略事先須建立大量比對樣式的資料庫,和建立最適合各別主機環境的基線樣式。本論文使用模糊認知圖(fuzzy cognitive maps, FCM)、C4.5決策樹(C4.5 decision tree)、成員函數(membership function)的建立和資料探勘(data mining)來完成網路行為資料的歸類、統計和建立標準基線(normal baseline)的技術,來建立正面表列(anomaly Rule)的網路入侵偵測系統(NIDS)。zh_TW
dc.description.abstractIn network intrusion detection system (NIDS), most systems make use of Misuse-Detection method to detect the network intrusion behaviors. This method requires a great number of built-in data for pattern comparison, and also cannot be classified every detected patterns in internet. The proposed anomaly-detection method just needs the network training instances to build the detective threshold. This method omits a great number of comparative data which need to be built in advance and a normal mode is set so that it can suit for most individual personal computers to detect an abnormal flow from networks. In this thesis we propose a network detection system of anomalous framework by using fuzzy cognitive maps techniques (FCM), C4.5 Decision Tree, membership function and data mining to work for the classifications and statistics. The system can use normal baseline to determine the threshold for the NIDS.en_US
