摘要
传统的网络入侵检测方法虽然可以检测到包含入侵信号的数据报文,但是检测速度和效率都难以适应高速的网络环境。论文应用否定匹配方法优化网络入侵检测中传统检测算法,设计了基于否定匹配的内容过滤算法,先对报文进行分段,然后过滤报文段内容中不含入侵信号的正常报文,再对怀疑含有入侵信号的报文段进行详细检测,提高了检测匹配速度和效率。
Traditional network intrusion detection method can be used to check the data message containing the intrusion signal,but the detection speed and efficiency are difficult to adapt high speed network environment.Negative pattern method is used to optimize the traditional detection algorithm in network intrusion detection,the content filter algorithm is designed based on negative pattern.Firstly,the message is divided into segment,and then the normal message segment which does not contain the intrusion signal is filtered,the message segment which is suspected containing intrusion signal is checked in detail to improve the detection matching speed and efficiency.
出处
《计算机与数字工程》
2015年第10期1834-1837,1864,共5页
Computer & Digital Engineering
基金
教育部"本科教学工程"地方高校第一批本科专业综合改革试点项目(教高司函〔2013〕56号
项目编号:ZG0388)
湖南省自然科学基金项目(编号:2jj3069)资助
关键词
否定匹配
模式匹配
内容分段
匹配次数
negative pattern
pattern match
content segmentation
matching number