摘要
入侵检测技术是安全防护的重要手段,而基于协议分析的入侵检测已经成为下一代入侵检测系统的关键技术之一。本文在分析网络入侵检测系统结构和传统的特征模式匹配技术的基础上,对协议分析的内容和过程进行了阐述,给出了基于协议分析的入侵检测系统的模型。并且分析基于模式匹配的入侵检测系统的不足,提出将模式匹配与协议分析相结合的方法。
Intrusion detection technique is an important safety precaution, meanwhile intrusion detection based on protocol has become one of the key technologies for the intrusion system detection of the next generation. The paper-based on the analysis of network intrusion detection's structure and traditional character pattern matching technology, explains the content and process of protocol analysis, based on protocol analysis, proposes a model of intrusion detection system. Furthermore,analyzes the limitations of intrusion detection system which is based on pattern matching, puts forward a method which protocol analysis and pattern matching are combined.
出处
《微计算机信息》
2010年第27期51-53,共3页
Control & Automation
关键词
入侵检测系统
模式匹配
协议分析
Intrusion Detection
Pattern Match
Protocol Analysis