摘要
随着Internet的高速发展,网络安全问题越来越引人注目,入侵检测系统越来越多地引起了人们的重视。本文提出一个基于混合模型的入侵检测系统,从系统调用,审计日志,网络协议三个层次,分析数据特征,建立相应的检测模型。使系统既可以检测新的攻击,又可以具有较低的误警率。
With the rapid development of Intemet, network security is more and more important, so more and more studies have been focused on intrusion detection systems. This paper presents an Intrusion Detecting with Multiple-models. System analyzes data from log, system call and network traffic, and builds multiple-models. It is given the character of ability to detect novel intrusion and low false positive.
出处
《贵阳学院学报(自然科学版)》
2006年第1期21-24,共4页
Journal of Guiyang University:Natural Sciences
关键词
入侵检测
异常检测
系统调用
Intrusion Detection
Abnormal Detection
System Call