摘要
入侵检测的方法很多,普遍存在误报率、漏报率高,难以做到实时性。该文介绍了当前主流的网络协议TCP/IP协议,给出了协议分析和命令解析的入侵检测方法,基本上解决了上述不足。
Nowadays,there are all kinds of ways of intrusion detection,which usually have some shortcoming such as high rate of wrong alert and lost alert,and are difficult to satisfy with the request of realtime.The article introduces current popular TCP/IP protocol and gives the method of Protocol Analysis and Command Parsing,which resolves above fault in the main.
出处
《计算机工程与应用》
CSCD
北大核心
2004年第18期159-162,共4页
Computer Engineering and Applications