To avoid having large false positive alarm rate, we have tolerated some high false negative alarms.


On the other hand, by choosing a higher threshold, we can decrease the false positive alarm rate at the cost of lower detection probability.


In another words, the 0% false negative probability PFN is accompanied by a high false positive alarm rate PFP.


It is clear that higher detection accuracy is achieved at a much lower cost of false positive alarm rate.




 Blood samples from 382 cases were aerobicly cultured by Bactec 9120 system. Pathogens isolated from thesamples were identified on Vitek AMS32. The results showed that 71 strains of 30 species of pathogens were isolated from 71 of 77 samples with positive alarm, and the average time of detection was 28. 4 h. Of all isolatedpathogens, there were 37 strains of & species of staphylococcus [32 strains of coagulasenegative staphylococcus(CNS) and 22 strains of methicillin resistant staphylococcus (MRS)].... Blood samples from 382 cases were aerobicly cultured by Bactec 9120 system. Pathogens isolated from thesamples were identified on Vitek AMS32. The results showed that 71 strains of 30 species of pathogens were isolated from 71 of 77 samples with positive alarm, and the average time of detection was 28. 4 h. Of all isolatedpathogens, there were 37 strains of & species of staphylococcus [32 strains of coagulasenegative staphylococcus(CNS) and 22 strains of methicillin resistant staphylococcus (MRS)]. No pathogens were isolated from all samples with negative alarm and the other 6 samples with positive alarm which had no obvious logarithmic growthphases and had been confirmed as false positive alarms. The results also showed that the recovery rate of the resincontaining vials was higher than that of the standard vials on patients being treated with antibiotics. It indicatedthat the proliferative speed of organism was an important factor affecting the time of positive alarm, and the reasonable selection of vials could improve the recovery rate. The simulated growth curves could be used to distinguish the false positive alarm, and CNS had become important pathogens of bacteremia and septicemia at present.  用Ｂａｃｔｅｃ９１２０全自动血培养系统检测了３８２例需氧血培养标本，分离出的病原菌用ＶｉｔｅｋＡＭＳ－３２进行鉴定和药敏试验。结果，系统阳性报警７７例，其中７１例分离出病原菌３０种７１株，平均阳性报警时间为２８．４ｈ。病原菌中葡萄球菌８种３７株，其中凝固酶阴性葡萄球菌（ＣＮＳ）３２株，耐甲氧西林葡萄球菌（ＭＲＳ）２２株。其余６例为假阳性报警，其模拟生长曲线多没有明显的对数生长期。阴性报警标本转种均无细菌生长。已用抗生素治疗病人的血培养，树脂瓶的阳性率高于普通瓶。表明，细菌增殖速度是影响系统阳性报警时间的重要因素。培养瓶选择不当可导致系统不能检测的假阴性。模拟生长曲线有助于鉴别假阳性报警。ＣＮＳ已成为当前菌（败）血症的重要病原菌。  A new encoding proposal which improves the compressed edge fragment sampling algorithm of Savage is proposed.In this new proposal,we overload the IP header fields which are correlative with the IP packet fragment to increase marking amounts.Moreover,64 paritycheck bits generated by 2 different hash functions are employed to reduce the false positive alarm.Then,we further give some optimization procedures to reduce computational complexity during reconstruction.Finally,the two algorithms,i.e.,the compressed... A new encoding proposal which improves the compressed edge fragment sampling algorithm of Savage is proposed.In this new proposal,we overload the IP header fields which are correlative with the IP packet fragment to increase marking amounts.Moreover,64 paritycheck bits generated by 2 different hash functions are employed to reduce the false positive alarm.Then,we further give some optimization procedures to reduce computational complexity during reconstruction.Finally,the two algorithms,i.e.,the compressed edge fragment sampling algorithm of Savage's(CEFS) and our new proposal named the improved compressed edge fragment sampling algorithm(ICEFS),are compared in three aspects,i.e.,the number of packets required for the victim to reconstruct the attack graph,computational complexity,and false positive alarm.The comparing results show that the new proposal ICEFS has much better performance than CEFS.For example the computational complexity during reconstruction of CEFS is m~8 and that of ICEFS is lower than 3m~2(where m is the number of attackers at the particular distance).When there are only 20 attackers at the same distance,the false positive rate of CEFS is nearly 0.99.When there are(1 000) attackers at the same distance,the false positive rate of ICEFS is still about zero.So ICEFS can be used in tracking large scale DDoS attacks.  针对Savage等人的压缩边采样算法,提出一种改进的压缩边采样算法,该算法利用IP包头与分段相关的字段作为重载字段,增加了边信息存储所需要的空间,降低了重构过程的计算复杂度,并采用64位Hash作为误差效验以显著降低多个攻击者同时存在时重构路径的虚警率,而且通过对重构过程的算法优化进一步降低了计算复杂度.对重构路径所需要的包数、计算量和重构路径的虚警率进行比较,结果证明,改进算法远远超过原算法.将原算法重构路径所需要的计算量(所需要计算的Hash次数)从m8降低到3m2(其中m为在相同距离的攻击源个数)以下.在同时有20个攻击者时,原算法虚警率已经高达0.99,使其不可用.而改进算法在同时有1 000个攻击者的情况下的虚警概率仍然近似为0.因此改进的压缩边采样算法能够很好地应用到大规模DDoS攻击源追踪中.  
