期刊文献+

基于漏洞扫描的入侵检测规则屏蔽方法研究

STUDY ON MASKING INTRUSION DETECTION RULES BASED ON VULNERABILITY SCANNING
下载PDF
导出
摘要 网络入侵检测系统的规则数在不断地增加,规则匹配的过程越来越复杂。在高速网络的环境下,NIDS(Network Intrusion Detection System)难以适应,产生漏检。将漏洞扫描与入侵检测进行融合,通过对保护对象扫描,找出存在的漏洞,根据漏洞信息将无用的规则屏蔽。实验结果表明,可以大量减少无用的检测规则;同时可以减少相应的警报信息。提高了检测效率、降低丢包率。 Rules of Network Intrusion Detection System (NIDS) are increasing, and rules' matching course is also becoming more compli- cated. NIDS is hardly to accommodate to this circumstances in high-speed network and often loses packets in detection. To integrate vulnera- bility scanning and NIDS is an effective method. Vulnerability scanning checks the protected object and finds its vulnerable information, and then NIDS masks useless rules according to the checked information. The experiment indicates that NIDS can reduce lots of useless rules and decrease corresponding alerts. It also shows that NIDS increases the efficiency and decreases the of packet loss rate,
出处 《计算机应用与软件》 CSCD 北大核心 2008年第7期259-260,282,共3页 Computer Applications and Software
关键词 入侵检测 漏洞扫描 屏蔽规则 Intrusion detection Vulnerability scanner Marking rules
  • 相关文献

参考文献7

  • 1Kumar G. Classification and detection of computer intrusion [ D ]. Indiana: Purdue University, 1995.
  • 2Robert F Erbacher, Kenneth L Walker, Deborah A Frincke. Intrusion and Misuse Detection in Large-Scale Systems [J]. IEEE Computer Graphics and Applications,2002 (2) : 38 - 48.
  • 3JULISCHK. Clustering Intrusion Detection Alarms to Support Root Cause Analysis [ J]. In ACM Transactions on Information and System Security,2003,6(4) :9.
  • 4李鹏,杨献荣,许丽华.网络漏洞扫描器的设计与实现[J].计算机工程,2003,29(8):116-117. 被引量:7
  • 5Common Vulnerabilities and Exposures. http://cve.mitre. org [ EB/ OL].
  • 6BugTraq. http://www. securityfocus.com/archive/1/description [ EB/ OL].
  • 7MIT Lincoln Laboratory. DARPA Intrusion Detection Evaluation Data Sets. Jan, 2002. http://www. ll. mit. edu/IST/ideval/data/data_index. html[ EB/OL].

二级参考文献2

  • 1ToxenB.Linux安全:入侵防范、检测和恢复[M].北京:机械工业出版社,2001-11..
  • 2ComerDE.计算机网络与互联网[M].北京:电子工业出版社,2001—04..

共引文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部