期刊文献+

基于协议状态分析的入侵检测系统 被引量:1

The Intrusion Detection System Based on the Protocol State Analysis
下载PDF
导出
摘要 提出了一种基于协议状态分析的入侵检测方法,不仅充分利用了协议的状态信息,而且考虑了相邻的数码包的内容状态,构造出协议状态序列,通过状态转换来检测入侵,有效地完成网络各层协议的分析,提高了检测的全面性、准确性和效率,实验结果表明是可行的。 This paper proposes an approach for the intrusion detection based on protocol state analysis, which not only makes full use of the protocol state information, but also considers the content state of the adjacent contextual packets, and constructs the state sequence of the protocol to detect the intrusion through the state transformation, fulfils the analysis effectively on the protocols at various layers of the network, enhances the completeness, accuracy and efficiency of the detection. The experimental results demonstrate that this approach is feasible.
出处 《科技情报开发与经济》 2007年第12期233-235,共3页 Sci-Tech Information Development & Economy
关键词 协议状态分析 协议状态机 协议异常检测 protocol state analysis protocol finite state machine protocol anomaly-based detection
  • 相关文献

参考文献3

二级参考文献3

  • 1Thomas H. Ptacek, Timothy N. Newsham Insertion, Evasion and Denial of Service: Eluding Network Intrusion Detection
  • 2Kevin Timm, IDS Evasion Techniques and Tactics.
  • 3W.Richard Stevens ,TCP/IP Illustrated, Volume 1 The Protocols.

共引文献3

同被引文献9

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部