摘要
提出了一个适用于小型网络的入侵检测系统框架,由包捕获器,包解码器,事件检测器和事件处理器构成,能对网络流量进行实时监控。特别在事件检测器中,针对采集的数据包头和数据包内容这两部分进行综合分析,采用规则检测技术进行异常行为检测,能更精确地检测入侵行为。通过实验证明了系统的检出率有明显提高,同时降低了误报率。
This paper gives a kind of frame of intrusion detection system suitable for small network.It consists of package capturer,package decoder,event detector and event processor.It inspects the network dataflow on real time,and especially establishes event detector based on rule detection.It gives the focus on the analysis on header and content of network packet,and the system can increase detection rate of intrusion action.It is proved that the system improves the detection rate and accuracy proved by experiments.
出处
《咸阳师范学院学报》
2010年第6期40-42,52,共4页
Journal of Xianyang Normal University
基金
陕西省教育厅科研基金项目(08JK481)
咸阳师范学院科研基金项目(06XSYK282)
关键词
网络安全
入侵检测
规则检测
network security
intrusion detection
rule detection