摘要
随着入侵检测技术和产品的发展,如何有效地评价入侵检测系统的有效性和可靠性成为了目前网络安全研究的一个热点问题。本文描述了目前入侵检测中一些常用的模型,对其优缺点进行了详细的描述。针对目前入侵检测系统的速度、准确率问题,结合入侵期望值模型,通过分析和推导给出了其值的最优参考值。给出了误报率、漏报率和入侵率与入侵个数乘积之间的关系,通过该关系可以得到入侵率与入侵个数乘积的值,其值对入侵检测系统的性能评估具有重要的意义。通过仿真实验验证了基于回报期望的入侵检测系统性能评估模型在入侵检测系统性能评估应用中的可行性。
It has become a hot topic in the current research of network security to evaluate the effectiveness and reliability of intrusion detection systems effectively with the development of technology and products of intrusion detection.This paper indicates the advantages and disadvantages of some intrusion detection models which are commonly used at present.An optimal reference value is given through analyzing and deriving an intrusion expectation model,which is different from the current problem of velocity and accuracy of the assessment of intrusion detection systems.Meanwhile,the relations of false alarm rate,false negative rate and the product of intrusion rate and intrusion number are given.Therefore,the product of intrusion rate and intrusion number can be given through the relation which is significant for the IDS capabilities evaluation.The feasibility of the return expectations-based IDS access model in assessing IDS is proved by the experiments of the Matlab software.
出处
《计算机工程与科学》
CSCD
北大核心
2011年第5期27-31,共5页
Computer Engineering & Science
基金
广东省自然科学基金资助项目(9151600301000001)
广东省科技计划资助项目(2009B010800026)
珠海市产学研资助项目(PC20082015)
茂名市科技计划重点资助项目(20091007)
关键词
误报率
漏报率
检测率
IDS
回报期望
false alarm rate
false negative rate
detection rate
IDS
return expectations