摘要
当前的入侵检测系统存在的虚警问题和报警量过大的问题严重影响了在实际中的应用效果。分析了系统弱点与入侵之间的关系,提出了弱点信息与入侵检测报警信息的关联的表示方法,给出了利用它们之间的关联提高入侵检测系统性能的实现框架。
The problems of false alerts and a large amount of alerts in intrusion detection systems (IDS) impact their effect greatly in application. The correlation between system vulnerability and intrusion is analyzed, and the expression methods are presented that cor- relate intrusion detection system alerts with system vulnerability information, and the implement approach to improve the performance of intrusion detection systems is given by their correlations.
出处
《计算机工程与设计》
CSCD
北大核心
2005年第3期573-574,585,共3页
Computer Engineering and Design
基金
国家自然科学基金项目(66272011)