| 1. | Then , a prototype system of this model has been implemented based on network monitoring and data mining . in this prototype many basic functions have been accomplished such as raw data capturing , behavior data preprocessing , mode definition , mode mining , mode maintenance and mode contrast . finally , this paper have researched mode update and anomaly identification tentatively and given some farther suggestions of improvement 论文中对该模型进行了整体规划和详细设计,并利用网络监听和数据挖掘等技术实现了一个网络访问行为分析的原型系统,完成了用户访问行为原始流量的捕获,行为数据预处理,行为模式的定义、挖掘、维护以及当前行为与历史行为模式比对等基本功能,并对模式更新、异常识别等方面进行了尝试性研究,提出了进一步完善模型的若干设想。 |