摘要
实验表明某一类型的网络攻击事件在相对集中的时间内相对活跃,此外都相对沉寂。对于基于特征的开源入侵检测系统Snort来说,如何提高速度以适应高速网络的发展是关键。文中对Snort的规则匹配算法及其多种改进算法进行比较分析,提出了一种利用反馈攻击入侵频度及老化因子的新算法,在消除入侵频度记录历史影响的基础上,实时的更新规则匹配顺序,从而提高规则的匹配速度。
Many experiments indicate that network attack event will be active in relatively concentrated time. In order to accommodate to the development of high-speed network,this article analyzes the rule-matching algorithm of Snort,an open source-code NIDS,and presents an algorithm by adjusting the sequence of rule matching through feedback of intrusion's frequentness,and the usage of an aging factor to dispel historic influence,consequently the rule matching speed is effectively increased.
出处
《计算机工程与应用》
CSCD
北大核心
2005年第32期133-135,共3页
Computer Engineering and Applications