摘要
研究了入侵检测响应中的延迟问题。通常,在入侵行为的检测和对入侵行为的响应之间有一个时间延迟,这个延迟时间范围可能是从几分钟到几个月,从而为入侵者提供了更多的机会。根据Cohen的研究,这种响应时间上的延迟常常带来严重的后果。作为这个问题的一种解决方法,提出了一种修改的入侵检测模型,这种模型包括了物理层的响应机理,从而能快速有效地对入侵做出响应,同时也给出了物理层设计的方案。
The delay problem of intrusion detection response was studied. Usually, there is a delay between detection of a possible intrusion and response to that intrusion. This delay in detection and response, ranging from minutes to months, provides a window of opportunity for attackers to exploit, According to Cohen's research, it often induces to serious result. As one solution to this problem, a modified IDS model was proposed that includes physical layer response mechanism, so as to respond rapidly and effectively. Furthermore, the details of the physical layer design was given,
出处
《计算机工程与设计》
CSCD
北大核心
2005年第11期3106-3108,共3页
Computer Engineering and Design