The paper explores the ai theories of developing the capp expert system , and fixes on the knowledge representation method of production rules , and the new thought of developing the knowledge base and the inference engine in the es tool clips , and introduces the theoretical knowledge of clips . the pape builds up the knowledge base about the process knowledge , invents the inference engine by the theories of control strategy of forward reasoning and rete pattern matching algorithm , with the result of improving the reliability of knowledge , the quality of inference and the efficiency of the searching . using the dynamic interface mechanism and the compiled dll , the paper embeds the clips program into the vc + + environment and carries out the mixed programming so as to achieve the data communication between the vc + + and clips 論文對開發(fā)capp專家系統(tǒng)的人工智能理論作了比較深入的探討,確定了產(chǎn)生式規(guī)則的知識表示方法和用專家系統(tǒng)開發(fā)工具clips來開發(fā)系統(tǒng)的知識庫和推理機(jī)的新思路。在闡述了clips理論知識的基礎(chǔ)上,確定了以產(chǎn)生式規(guī)則構(gòu)建工藝知識庫,以正向推理的控制策略和里德算法的匹配模式建立推理機(jī),從而提高了知識的可靠性、推理質(zhì)量與搜索的效率。論文利用windows環(huán)境下的動態(tài)接口機(jī)制,調(diào)用已編譯好的動態(tài)鏈接庫clips . dll ,把所開發(fā)的clips程序嵌入到vc + +中再進(jìn)行混合編程,實現(xiàn)了vc + +與clips程序的數(shù)據(jù)通信,成功地構(gòu)建了capp專家系統(tǒng)。
So a fast pattern matching algorithm on mass string assemble has been proposed to solve the problem of fuzzy matching between a string pattern and a string assemble . to make the algorithm cost - effective in space and time , we have developed an optimized trie - tree structure to store the string assemble and introduced the knuth - morris - pratt ( kmp ) and finite - automata ( fa ) string matching thought to our algorithm . the algorithm has been describled in details and the cost of space and run time has been analized in the thesis 為了實現(xiàn)漢字輸入碼的不完整輸入,解決帶有模糊輸入符的字符串模式與一個字符串集合之間的匹配問題,論文在第三章提出一種海量字符串集合的模式匹配算法,給出了算法的具體實現(xiàn)和復(fù)雜度分析,并且提出一種優(yōu)化的檢索樹結(jié)構(gòu)來存儲字符串集合以節(jié)省內(nèi)存空間。為了提高算法的運(yùn)行速度,算法還引入了kmp模式匹配和有限自動機(jī)匹配的思想。
In the detection of protocol analysis model , we mainly studied the fragment reassembly of ip packet on the bases study of tcp / ip protocol . in the detection of pattern match model , we analyzed several kinds of pattern match algorithms such as : kmp , bm , bmh and multiple pattern match algorithms ( wang 2002 ) 在基于協(xié)議分析的檢測方法中,從tcp / ip協(xié)議族的層次結(jié)構(gòu)出發(fā),主要分析了ip包的分片重組技術(shù);在基于模式匹配的檢測方法中,主要分析了多種模式匹配算法: kmp 、 bm 、 bm的改進(jìn)算法以及多模式匹配算法。
After comparing several pattern matching algorithms , we put forward a kind of improved pattern matching algorithm called bmhsy , then basing on some research on network intrusion system and host intrusion system , we give a hybrid intrusion detection system , which combines the advantage of bm , bmh and bmhs , at last present performance analysis in actual environment . the main work of this paper is as follows . ( 1 ) by comparing bm , bmh and bmhs pattern matching algorithm , we give a improved pattern matching algorithm which used of the thought of bm algorithm , and combined the advantage of bmh and bmhs 本論文通過比較入侵檢測中常用的幾種模式匹配算法,提出了一種bmhsy算法,它綜合bmh和bmhs的特點(diǎn),并針對其效率問題進(jìn)行了改進(jìn);在研究基于主機(jī)的入侵檢測技術(shù)和基于網(wǎng)絡(luò)的入侵檢測技術(shù)的基礎(chǔ)上,結(jié)合兩種技術(shù)特點(diǎn),采用分布式混合型體系結(jié)構(gòu),研制了一個混合入侵檢測系統(tǒng),對其實際運(yùn)行結(jié)果和性能進(jìn)行了分析。
So a fast pattern matching algorithm on mass string assemble has been proposed to solve the problem of fuzzy matching between a string pattern and a string assemble . the algorithm has been described in detail and the cost of space and run time has been analyzed in chapter 5th of the thesis 為了實現(xiàn)漢字輸入碼的不完整輸入,解決帶有模糊輸入符的字符串模式與一個字符串集合之間的模糊匹配問題,論文在第五章提出了一種字符串集合的模糊匹配算法,給出了算法的具體實現(xiàn)和復(fù)雜度分析。
First , model , constitutes , category , trend and problem of ids is presented , and then pattern match which is applied widely is introduced from the aspect of theory and technology . principle and performance data of three pattern match algorithms such as bm , bmh and ac _ bm are discussed in detail . previous two algorithms are realized by programming 本文首先介紹了入侵檢測系統(tǒng)的模型、組成、分類、發(fā)展趨勢以及面臨的眾多問題,然后從原理上、技術(shù)上介紹了目前使用最廣泛的模式匹配檢測方法,以常用的網(wǎng)絡(luò)入侵檢測系統(tǒng)snort為例,詳細(xì)討論了bm 、 bmh和ac bm三種模式匹配算法的基本思想以及性能參數(shù),并且編程實現(xiàn)了前兩種算法。
The present self - adaptive intrusion detection model overcomes the in - completeness of the intrusion rule base constructed by experts with the limited domain knowledge . on the other hand , it can construct and update efficiently the intrusion rule base , and detect timely the network intrusion activity . based on the analysis of the current network intrusion approach and observation of the characteristics of network packets , we design a new multiple pattern matching algorithm combining the boyer - moore pattern matching with the finite state automata , and present an efficient network intrusion detection approach 在深入分析現(xiàn)有入侵檢測方法的基礎(chǔ)上,通過研究網(wǎng)絡(luò)數(shù)據(jù)包廣西大學(xué)碩十學(xué)位論文一基于模式匹配和數(shù)據(jù)挖掘的網(wǎng)絡(luò)入侵檢測系統(tǒng)方泣的研究的特點(diǎn),采取將傳統(tǒng)的bm模式匹配算法與有限狀態(tài)自動機(jī)相結(jié)合的方法,我們設(shè)計一個新的多模式匹配算法,進(jìn)而提出一種高效的網(wǎng)絡(luò)入侵檢測方法。