Computer Science ›› 2017, Vol. 44 ›› Issue (9): 136-141, 161.doi: 10.11896/j.issn.1002-137X.2017.09.027

Network Anomaly Detection Model Based on Time-varying Weighted Markov Chain

WANG Xiao, QI Yong and LI Qian-mu   

  • Online:2018-11-13 Published:2018-11-13

Abstract: With the rapid development of the Internet,the network intrusion events are becoming more and more frequent,and the instruction detection is of great significance to the protection of network security.In view of the urgent demand of real-time instruction detection,a model of network instruction detection based on time-varying weighted Markov chain model was proposed in this paper.This model uses the combined state sequence to describe state transition.The log event generated by the DARPA2000 data set on the NT system was used as the experimental data to carry out simulation experiments,and the time-varying weighted Markov chain model were compared. The simulation results show that the model mentioned in this paper can be used for real-time instruction detection,which has high accuracy,strong robustness,and can effectively reduce the false detection rate.

Key words: Network security,Weighted Markov,Time varying model,Instruction detection

