文档介绍:3
2 2 2
2
2
2
2
第 26卷第 2期计算机应用研究 Vol. 26 No. 2
2009年 2月 App lication Research puters Feb. 2009
基于 Ne tFlow 的用户行为挖掘算法设计
刘璇, 张凤荔, 叶李
(电子科技大学计算机科学与工程学院, 成都 610054)
摘要: 网络安全技术以防火墙、入侵检测等为主,较少从网络用户行为角度考虑可能进行的破坏行为。针对
此问题,Flow采集、统计,设计了表示用户行为特征的数据结构及统计模式,获得了行为的具体信
息,建立了在一定时间粒度下的行为数据库;并在行为数据库的基础上,设计出适用于用户行为特征的聚类挖掘
算法,定义了用户行为距离,确定各个用户的网络行为模式。实验表明,所设计算法可有效挖掘用户的网络行
为,为管理、分析用户行为提供了有效依据。
关键词: NetFlow; 数据挖掘; 用户行为; 行为距离
中图分类号:2 T2P3 文献标志2码2: A 文章编号: 1001 3695 (2009) 02 0713 03
2 2
2 1
M ining algorithm design on user behavior based Flow
L IU Xuan, ZHANG Feng li, YE L i
(School puter Science & Engineering, University of Electronic Science & Technology of China, Chengdu 610054, China)
Abstract: Most of the work security technologiesmainly focus on firewall, intrusion detect system ( IDS) , and give
less consideration work malicious behavior from user behavior angle In accordance with aforementioned p roblem, de
signed and defined the structure of user behavior feature and the pattern of statistics, set up user behavior’s database and got
user behavior’s detail information. The data were based Flow collection and statistics. According to the information in
database, designed the clustering algorithm to suit for the user behavior structure and define distance of user behavior, to es
tablish user’work behavior pattern. Experiment results indic