期刊文献+

基于动态Cache策略优化Snort检测引擎性能研究

RESEARCH ON PERFORMANCE OPTIMIZATION OF SNORT DETECTION ENGINE BASED ON DYNAMIC CACHE STRATEGY
下载PDF
导出
摘要 提出了一种动态Cache策略,将最近一段时间内经常用到的少量规则结点指针存储在一个Cache块中。当攻击密度上升到一定阈值时,在Snort检测引擎中动态加载Cache块,接下来捕获的每一个数据包都首先和Cache块中存储的指针所指向的规则结点进行匹配。当网络攻击密度降低到一定阈值时,在Snort检测引擎中动态卸载Cache块,避免攻击密度较低时二次匹配带来的额外开销。实验表明,动态Cache策略可以提高Snort检测引擎在高强度攻击下的检测效率,降低漏报率。 A dynamic Cache strategy is put forward, in which the recent frequently used rule node pointers are stored in a Cache block. When the density of intrusion attack is enhanced to some point, the Cache is dynamically loaded in Snort detection engine, and each packet captured is firstly matched with the rule node in Cache block. When the density of intrusion attack is degraded to some point, the Cache block is unloaded from Snort detection engine dynamically, so that the extra cost caused by twice rule matching is avoided. The experiments show that the dynamic Cache strategy can improve the detection efficiency under high attack density and degrade the rate of missing alert.
作者 张雪松
出处 《计算机应用与软件》 CSCD 北大核心 2008年第3期260-262,共3页 Computer Applications and Software
关键词 入侵检测 规则匹配 高速缓存 Intrusion detection Rule matching Cache
  • 相关文献

参考文献3

二级参考文献8

  • 1steven J.Scott Snort Install Manual-Snort,MYSQL,Redhat7.2
  • 2Brian Caswell,Jay Beale等著,Snort2.0 Intrusion Detection,国防工业出版社,2004
  • 3.[EB/OL].Http://www.snort.org.,.
  • 4Neil Desai. Increasing Performance in High Speed NIDS.look at Snort's Internals, http ://www.cis.udel.edu/~zhi/www.docshow.net, 2002-03.
  • 5Brian Caswell,Jay Beale,James C Foster.Snort 2.0 Intrusion Dectection[M].Syngress Publishing, Inc, 2003.
  • 6韩东海 王超 李群.入侵监测系统实例剖析[M].清华大学出版社,2002-05..
  • 7李镇江,戴英侠,陈越.IDS入侵检测系统研究[J].计算机工程,2001,27(4):7-9. 被引量:33
  • 8任晓峰,董占球.提高Snort规则匹配速度方法的研究与实现[J].计算机应用,2003,23(4):59-61. 被引量:13

共引文献39

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部