Correctly understanding the various threats faced by the network and effectively preventing and solving them to achieve true network security has become the primary task of current network development. This article used the attacker's perspective to launch simulation attacks on the system, in order to determine its response ability, defense level, and affected range when facing intrusion attacks. The exposed weak points are strengthened to enhance the system's security defense capabilities. Meanwhile, through the ability of machine self-learning, the attack behavior and response strategies are accumulated into an attack script library, thereby improving the diversity and real-time updates of simulated attack forms. Ultimately, through continuous white box testing, the entire attack chain information was visualized to achieve faster and more accurate hunting. The average repair time for high-risk vulnerabilities was 26.8 h, and the average repair time for medium risk vulnerabilities was 17.8 h. This article can proactively identify vulnerability points, evaluate the system's risk resistance after an attack and demonstrate the degree of impact on business stability of the system after being attacked by an intrusion.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Optimization Exploration of Network Intrusion Detection System by Fusion Data Mining

  • Xiaoyan Wei,
  • Fan Xia,
  • Bo Jin,
  • Zheng Yu,
  • Zhiyong Zha,
  • Huan Xu,
  • Haohua Meng,
  • Dongling Xiao,
  • Chenxi Dong,
  • Dai Hou

摘要

Correctly understanding the various threats faced by the network and effectively preventing and solving them to achieve true network security has become the primary task of current network development. This article used the attacker's perspective to launch simulation attacks on the system, in order to determine its response ability, defense level, and affected range when facing intrusion attacks. The exposed weak points are strengthened to enhance the system's security defense capabilities. Meanwhile, through the ability of machine self-learning, the attack behavior and response strategies are accumulated into an attack script library, thereby improving the diversity and real-time updates of simulated attack forms. Ultimately, through continuous white box testing, the entire attack chain information was visualized to achieve faster and more accurate hunting. The average repair time for high-risk vulnerabilities was 26.8 h, and the average repair time for medium risk vulnerabilities was 17.8 h. This article can proactively identify vulnerability points, evaluate the system's risk resistance after an attack and demonstrate the degree of impact on business stability of the system after being attacked by an intrusion.