期刊文献+

一种滥用入侵检测系统改进模型

An Improved Model of Misuse Intrusion Detection System
下载PDF
导出
摘要 滥用入侵检测系统因其虚警车低而在网络安全上被广泛应用,但通常攻击规则库更新的方式 (手工)是制约该检测系统发展的瓶颈.本文通过分析、挖掘审计信息,提出一种使系统自适应准实时加入新 攻击规则的方案,从而降低滥用入侵检测系统的漏警率,提高效率. The MIDS is widely used for the network security because of its low false alarm rate. However, its developmental bottle-neck results from the manual means of attacking rule base being updated. A scheme that the new attack rules can be added to the system adaptively and near real-timely is presented in this paper by analysing and processing its auditing information, which can be available for lowering the lost alarm rate of MIDS and enhancing its efficiency.
作者 程志华 郭伟
出处 《空军雷达学院学报》 2003年第1期48-50,共3页 Journal of Air Force Radar Academy
关键词 滥用入侵检测 攻击 虚警率 规则库 网络安全 实时 系统 高效率 自适应 方案 network security misuse intrusion detection system (MIDS) audit information rule base
  • 相关文献

参考文献3

二级参考文献7

  • 1Agrawal R, Strikard R. Fast Algorithms for Mining Association Rules.In Proceedings of the 20th ULDB Conferance,Santiago, Chile, 1994
  • 2Klemettinen M,Mannila H,Ronkainen P, et al.Finding Interesting Rules from Large Sets of Discovered Association Rules. In Proceedings of the 3rd Intemational Conference on Information and Knowledge Management(CIKM'94),Gainthersburg, MD, 1994:401-407
  • 3Stolfo S L, Promidis A L.Tselepis S,et al. JAM:Java Agents for Metalearning Overdistributed Databases. In Proceedings of the 3rd International Conference on Knowledge Discovery and Data Mining,Newport Beach,CA,AAAI Press, 1997-08:74-81
  • 4赵海波,李建华,杨宇航.网络入侵智能化实时检测系统[J].上海交通大学学报,1999,33(1):76-79. 被引量:37
  • 5刘美兰,姚京松.审计跟踪与入侵检测[J].计算机工程与应用,1999,35(7):12-15. 被引量:12
  • 6刘明吉,王秀峰,黄亚楼.数据挖掘中的数据预处理[J].计算机科学,2000,27(4):54-57. 被引量:125
  • 7黄辰林,赵辉,胡华平.基于分布自治代理的层次入侵检测系统设计[J].计算机工程与应用,2001,37(6):47-49. 被引量:12

共引文献72

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部