期刊文献+

Snort匹配机制的改进 被引量:2

Improvement of Matching Mechanism in Snort
下载PDF
导出
摘要 基于规则的模式匹配是Snort检测引擎的主要机制,本文在结合协议分析和模式匹配的基础上,对Snort匹配机制进行了改进。首先对从网络中获取的数据包进行预先处理,利用协议分析技术对数据包进行高层应用协议分析;根据分析的结果,再利用提出的新型的模式匹配算法,对数据包中的其他相应信息进行模式匹配,从而显著地提高了Snort规则匹配的效率。测试表明,改进过的Snort在性能上得到了提高。 The pattern matching based on rule is the main mechanism in the detection engine of Snort. Based on the combination of protocol analysis and pattern matching, we improved the matching mechanism in snort. Firstly, we foreclose the data packet gains from the network, analyzing the data packet by using the technology of protocol analysis; based on the result, we match the other corresponding information of data packet by using a new algorithm of pattern matching; all of these can raise the efficiency of rule matching in Snort obviously. Finally a performance test is held, which shnws that the improved snort has better performance.
出处 《微计算机信息》 2009年第6期106-107,80,共3页 Control & Automation
关键词 入侵检测 协议分析 规则树 模式匹配 Intrusion Detection Protocol Analysis Rule Tree Pattern Matching
  • 相关文献

参考文献3

二级参考文献5

  • 1Hochberg J Jackson K, Stallings C,et al.NADIR:An Automated System for Detecting Network Intrusion and Misuse.Computers and Security, 1993,12(3):235-248.
  • 2Knuth DE , Morris JH, Pratt VR. Fast Pattern Matching in Strings[J].SIAM Journal on Computer, 1977,6(2) :323-350.
  • 3Boyer RS , Moore JS. A Fast String Searching Algorithm[J].Communications of the ACM ,1977,20(10) :762-772.
  • 4Crochemorc M,Rytter W.Text Algorithms.Oxford University Press. 1994.
  • 5Aho AV,Corasick MJ.Efficient String Matching:An Aid to Bibliographic Search. Communications of the ACM ,1975,18(6) :333-340.

共引文献34

同被引文献11

引证文献2

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部