期刊文献+

复合式入侵检测方法的研究

Innovation to hybrid intrusion detection methodology
下载PDF
导出
摘要 所提出的复合式入侵检测算法是基于行为建模算法和模式匹配算法两种入侵检测算法的有效结合,其中行为建模算法扩展了基于异常的入侵检测算法,而模式匹配算法完全实现了基于特征的入侵检测算法.自适应的行为建模算法根据用户的行为和程序的行为建立合法的行为模板,而不需要任何人工干预.两种入侵检测算法能够有效的降低误报率的发生.采用Servlet Filter技术的安全代理是一个具有一定入侵分析功能的智能插件. The hybrid intrusion detection algorithm proposed here is based on the effective integration of behavior modeling and pattern matching, where behavior modeling extends anomaly-based intrusion detection algorithm and pattern matching implements signature-based intrusion detection algorithm. The adoption of self-learning behavior modeling has the capability to determine the legitimate profiles according to user activities or program activities without any intervention of human security expert. The combination of the two intrusion technologies has dramatically reduced false positive and false negative alarms. A Servlet Filter-based security agent is an intelligent plugin with the basic ability of intrusion analysis.
出处 《天津理工大学学报》 2007年第1期63-65,共3页 Journal of Tianjin University of Technology
基金 天津市科技攻关项目(0431079R)
关键词 入侵检测 行为建模 模式匹配 intrusion detection behavior modeling pattern matching
  • 相关文献

参考文献3

  • 1[1]Kumar S,Spafford E H.A pattern matching model for misuse intrusion detection[EB/OL].(1994-10)[2005-3-10].http://homes.cerias.purdue.edu/~ spaf/techreps/ncsc.ps.
  • 2[2]Ghosh A K,Wanken J,Charron F.Detecting anomalous and unknown intrusions against programs[EB/OL].(1998-5)[2005-6-20].http://www.cigital.com/papers/download/acsac98.pdf.
  • 3[4]Im EG,In HP,Choi DS,et al.Adaptation policies for web server intrusion-tolerant system[EB/OL].(2005-5-10)[2006-10-09].http://ietcom.oxfordjournals.org/cgi/content/refs/E88-B/8/3462.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部