摘要
网络入侵检测系统的规则数在不断地增加,规则匹配的过程越来越复杂。在高速网络的环境下,NIDS(Network Intrusion Detection System)难以适应,产生漏检。将漏洞扫描与入侵检测进行融合,通过对保护对象扫描,找出存在的漏洞,根据漏洞信息将无用的规则屏蔽。实验结果表明,可以大量减少无用的检测规则;同时可以减少相应的警报信息。提高了检测效率、降低丢包率。
Rules of Network Intrusion Detection System (NIDS) are increasing, and rules' matching course is also becoming more compli- cated. NIDS is hardly to accommodate to this circumstances in high-speed network and often loses packets in detection. To integrate vulnera- bility scanning and NIDS is an effective method. Vulnerability scanning checks the protected object and finds its vulnerable information, and then NIDS masks useless rules according to the checked information. The experiment indicates that NIDS can reduce lots of useless rules and decrease corresponding alerts. It also shows that NIDS increases the efficiency and decreases the of packet loss rate,
出处
《计算机应用与软件》
CSCD
北大核心
2008年第7期259-260,282,共3页
Computer Applications and Software
关键词
入侵检测
漏洞扫描
屏蔽规则
Intrusion detection Vulnerability scanner Marking rules