摘要
针对现有入侵检测系统采用单一检测模式难以有效地解决漏报和误报问题,本文从开源软件snort系统开始分析,提出一种混合式入侵检测系统SHIDS(A Serial Hybrid Intrusion Detection System),将两种不同检测模式相结合,较好解决单一检测模式不足,同时对未知病毒也进行了预判。实验结果显示,SHIDS比误用检测系统漏报率低,检测速率较快;比异常检测误报率低,解释性也较强。
For existing intrusion detection system using a single test mode is difficult to tackle the issue of omission and misstatement,this paper proposed a new SHIDS(Serial Hybrid Intrusion Detection System).We start from the open source software SNORT and then combines two different detect pattern together.The result shows that SHIDS has covers the shortage of single test mode while unknown viruses have also been pre-judgment:1) SHIDS has a lower omission rate and a faster detection speed 2) SHIDS has a lower misstatement rate and a higher explanatory.
出处
《微计算机信息》
2012年第1期130-131,59,共3页
Control & Automation