摘要
针对现有入侵检测技术的不足,提出了基于数据解析的入侵检测技术和利用有限自动机实现数据解析的方法。将大量的数据解析为代表各种网络或系统活动的特征信息序列,使得检测分析过程简单高效。由于解析自动机的可扩展性,使其具备一定的异常检测能力。
According to the defects of existing intrusion detection technology,the intrusion detection technology based on data parsing and the finite automaton to implement data parsing were proposed.A lot of data would be parsed to characteristic information sequence to represent various network or system activity,making the detection process simple and efficient.Because of the scalability of finite automaton,the intrusion detection system was made to be of certain anomaly detection capabilities.
出处
《计算机应用》
CSCD
北大核心
2008年第S2期274-276,共3页
journal of Computer Applications
关键词
入侵检测
数据解析
特征信息序列
有限自动机
intrusion detection
data parsing
sequence of characteristic information
finite automaton