期刊文献+

一种混合式入侵检测系统

A Hybrid Intrusion Detection System
下载PDF
导出
摘要 针对现有入侵检测系统采用单一检测模式难以有效地解决漏报和误报问题,本文从开源软件snort系统开始分析,提出一种混合式入侵检测系统SHIDS(A Serial Hybrid Intrusion Detection System),将两种不同检测模式相结合,较好解决单一检测模式不足,同时对未知病毒也进行了预判。实验结果显示,SHIDS比误用检测系统漏报率低,检测速率较快;比异常检测误报率低,解释性也较强。 For existing intrusion detection system using a single test mode is difficult to tackle the issue of omission and misstatement,this paper proposed a new SHIDS(Serial Hybrid Intrusion Detection System).We start from the open source software SNORT and then combines two different detect pattern together.The result shows that SHIDS has covers the shortage of single test mode while unknown viruses have also been pre-judgment:1) SHIDS has a lower omission rate and a faster detection speed 2) SHIDS has a lower misstatement rate and a higher explanatory.
作者 彭建 刘凯
出处 《微计算机信息》 2012年第1期130-131,59,共3页 Control & Automation
关键词 入侵检测 snort异常检测 Payload误用检测 串行混合式入侵检测 Intrusion detection snort anomaly detection Payload misuse detection serial hybrid Intrusion Detection
  • 相关文献

参考文献3

二级参考文献17

  • 1Wu Sun, Manber U. A Fast Algorithm for Multi - Pattern Searching[ R ]. Arizona: University of Arizona, 1994.
  • 2Boyer R S,Moore J S. A fast string searching algorithm[J]. Communications of the ACM, 1977,20:762 -772.
  • 3Navarro G, Raffinot M. Flexible Pattern Matching in Strings[M].中科院计算所网络信息安全研究组译.北京:电子工业出版社,2007.
  • 4Snort2.6.0[ CP/OL]. [2006 - 12 - 05]. http://www. snort. orig.
  • 5Roesch M. The Story of Snort: Past, Present and Future[CP/ OL]. 2005. http://www. net - security. org/article. php? id = 860.
  • 6Beheshti M, Han J, Kowalski K, et al. Packet Information Collection and Transformation for Network Intrnsion Detection and Prevention[C]//Internatioal Sympositum on Telecommunicarions. [s. l. ] : IEEE,2008:42 - 48.
  • 7Tuck N, Sherwood T, Calder B, et al. Deterministic Memory Efficient String matching Algorithms for Intrusion Detection [C]//In Proceedings of IEEE Infocom. Hong Kong: [s. n. ], 2004.
  • 8Garuba M, Liu Chunmei, Fraites D. Intrusion Techniques: Comparative Study of Network Intrusion Detection Systems [C]//Fifth International Conference: New Generations. [ s. l. ] : IEEE Computer Society, 2008 : 592 - 598.
  • 9Caswell B,Iay Beale C Foster,Posluns J. Snort2.0入侵检测[M].宋劲松,等译.北京:国防工业出版社,2004.
  • 101999 DARPA intrusion detection evaluation data set [ DB/ OL]. [2007 - 04 - 09]. http://www. darpa. mil.

共引文献20

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部