摘要
设计并实现了一个基于专家系统的网络入侵特征检测系统.针对当前入侵检测推理机制中存在的时间冗余性问题,在入侵检测推理过程中采用了Rete模式匹配算法,对推理机制进行了优化.实验结果表明,该系统在检出率和检测效率上要明显高于未采用Rete模式匹配算法的系统,采用Rete模式匹配算法能有效地克服时间冗余性问题,并改善了系统的性能.
We design and realize a signature intrusion detection system based on Expert System. Faceing the redundancy of time in the reasoning of intrusion detection,we apply a new algorithm called Rete pattern matching algorithm, which optimizes the reasoning principle of the system. From the data in the experiment, we can see the rate of detection and detection efficiency of this intrusion detection system are obviously higher than the system which don't apply the Rete algorithm,which shows that using Rete pattern matching algorithm can overcome the redundancy of time effectively and improve the system performance.
出处
《武汉大学学报(理学版)》
CAS
CSCD
北大核心
2004年第3期355-359,共5页
Journal of Wuhan University:Natural Science Edition
基金
国家863计划资助项目(863- 306- ZT05- 02)
关键词
入侵检测
专家系统
时间冗余性
Rete模式匹配算法
intrusion detection
expert system
redundancy of time
Rete pattern matching algorithm