摘要
在设计入侵检测系统时,针对传统入侵检测系统中采用的模式匹配方法计算量大、漏报率和误报率高等缺点,提出基于协议分析和规则匹配相结合的方法,通过高度规则的网络协议优势来减少系统的工作复杂度,有效地提高检测的准确性并降低漏报率。
In the period of designing intrusion detection system,with the traditional mode matching method whose computation is great and which has high missing rate and high false alarm rate,puts forward a new method which combines protocol analysis with rule match.With the advantage of network protocols which follow standards,the new method can reduce the working complexity of our system.So the method can effectively increase the accuracy of detection and decrease the missing rate.
出处
《现代计算机》
2011年第16期56-60,共5页
Modern Computer
基金
武汉科技大学大学生创新基金(No.10ZRZ041)
关键词
入侵检测
协议分析
网络安全
Intrusion Detection
Protocol Analysis
Network Security