摘要
文中讨论了误用和异常入侵检测技术存在的不足,提出结合误用检测和异常检测的入侵检测系统模型,该系统利用规则匹配检测已知入侵,利用免疫算法检测未知入侵并更新规则数据库,检测效率较高。
The drawbacks of misuse intrusion detecting and anomaly intrusion detecting technologies were presented. An intrusion detection system which combined misuse detection and anomaly detection was designed. This system detects known intrusions by matching rules, and it utilizes Immune Algorithm to detect unknown intrusions and update the Rule Database. The system is efficient in intrusion.
出处
《信息安全与通信保密》
2006年第8期128-130,共3页
Information Security and Communications Privacy
关键词
误用检测
异常检测
规则匹配
免疫算法
misuse detection anomaly detection rule match immune algorithm