摘要
为提高对未知攻击的检测能力,克服由于"正常"与"异常"界线模糊引起的误报与漏报,提高入侵检测系统的自适应能力,基于danger theory提出以危险信号作为入侵检测的协同检测信号的方法,并运用粗糙集理论,实现了对危险信号的测定。同时,阐述了危险信号在入侵检测的协同检测中的控制策略及系统的逻辑结构和处理流程。
To increase the detection ability of unknown intrusion and overcome false negative rate and false positive rate when boundary between normal and abnormal was fuzzy and improve the adaptability of intrusion detection system, a co- stimulate intrusion detection with danger signal based on danger theory was presented. A method of determining the danger signals based on rough set theory was proposed and a control strategy of danger signal used in co-stimulate intrusion detection was brought forward. The logic structure of this system and the control flow of this system were proposed,.
出处
《计算机应用》
CSCD
北大核心
2008年第7期1784-1785,1806,共3页
journal of Computer Applications
关键词
危险信号
协同检测
入侵检测
免疫
danger signal
co-stimulate
intrusion detection
immune