Network intrusion early warning model based on D-S evidence theory
Zhai Jian-qiang, Junfeng Tian, Ruizhong Du, Jiancai Huang · 2004
Application of data fusion technique in intrusion detection is the trend of next-generation intrusion detection system (IDS). In network security, adopting security early warning technique is feasible to effectively defend against attacks and attackers. To do this, correlative information provided by IDS must be gathered and the current intrusion characteristics and situation must be analyzed and estimated. This paper applies D-S evidence theory to distributed intrusion detection system and propose a early warning model which fuses information from detection centers, makes clear intrusion situation and improves the early warning capability and detection efficiency of the IDS.