期刊文献+

基于改进正则表达式规则分组的内网行为审计方案

Audit scheme for intranet behavior based on improved regular expression rule grouping
下载PDF
导出
摘要 针对网络安全审计中对应用层协议审计能力不足的问题,提出一种基于改进正则表达式(RE)规则分组的内网行为审计方案。首先,通过正则表达式对需审计的协议进行描述,并设置相关参数,使内网中出现频率高和审计中相对重要的协议状态在正则表达式描述集中取得高优先级;然后,在正则表达式交互值小的前提下,尽可能地将高优先级协议状态表达式构建到相同自动机分组中以生成审计引擎;最后,根据审计需求,改变相关参数,实现对内网行为的安全审计。实验结果显示,所提出的自动机构建算法在转化时的状态数缩减为经典非确定有限状态自动机(NFA)转化算法Thompson的10%~20%,检测时的吞吐量约为传统自动机分组引擎的8到12倍;所提审计方案能够满足对应用层协议进行安全审计的需求,具有较高的准确性和效率。 In view of the insufficient ability of application layer protocol audit, an intranet behavior audit scheme based on improved Regular Expression (RE) rule grouping was proposed. First, the protocol needed to be audited was described by regular expression, and the relevant parameters were set, so that the states of high frequency protocols and the relative importance protocols of the audit in the intranet had the high priority in the RE set. Then, under the premise of the small interaction value of the regular expression, the high priority protocol state expression was built into the same automaton group to generate the audit engine as much as possible. At last, according to the audit requirements, the relevant parameters were changed to achieve security audit of the intranet behavior. Experimental results showed that, compared with the classic Nondeterministie Finite Automaton (NFA) algorithm named Thompson, the state number of the transformation of the proposed automata construction algorithm was reduced to 10% to 20%, and the throughput became 8 to 12 times as much as the throughput of the traditional automata grouping engine in detection. The proposed audit scheme can satisfy the demand of the application layer protocol in safety audit with high accuracy and efficiency.
出处 《计算机应用》 CSCD 北大核心 2016年第8期2241-2245,共5页 journal of Computer Applications
基金 国家自然科学基金资助项目(61100042) 湖北省自然科学基金资助项目(2015CFC867) 信息保障技术国防重点实验室基金资助项目(KJ-13-111)~~
关键词 正则表达式 协议状态 安全审计 自动机分组 需求选择 regular expression protocol state security audit automaton grouping demand choice
  • 相关文献

参考文献11

  • 1付钰,李洪成,吴晓平,王甲生.基于大数据分析的APT攻击检测研究综述[J].通信学报,2015,36(11):1-14. 被引量:79
  • 2CHEN P, DESMET L, HUYGENS C. A study on advanced persis- tent threats [ C]// CMS 2014: Proceedings of the 15th IFIP TC 6/ TC 11 International Conference on Communications and Multimedia Security, LNCS 8735. Berlin: Springer-Verlag, 2014:63-72.
  • 3VIRVILIS N, GRITZALIS D A. The big four -- what we did wrong in advanced persistent threat detection? [ C]//ARES '13: Proceed- ings of the 2013 International Conference on Availability, Reliability and Security. Washington, DC: IEEE Computer Society, 2013: 248 - 254.
  • 4YANG G, TIAN Z, DUAN W. The prevent of advanced persistent threat [ J]. Journal of Chemical and Pharmaceutical Research, 2014, 6(7) : 572 -576.
  • 5XIA Q. Log-based network security audit system research and design [J]. Advanced Materials Research, 2010, 129-131:1426 - 1431.
  • 6LU T, LIU P. Multi-Agent network security audit system based on information entropy [ C]// SWS 2010: Proceedings of the 2010 IEEE 2nd Symposium on Web Society. Piscataway: IEEE, 2010: 367 -371.
  • 7HUANG X, HUENG X, QUAN P. Research on firewall system for colffidential network [ J]. Advanced Materials Research, 2012, 434-440:4279-4283.
  • 8张树壮,罗浩,方滨兴.面向网络安全的正则表达式匹配技术[J].软件学报,2011,22(8):1838-1854. 被引量:28
  • 9YU F, CHEN Z F, DIAO Y L, et al. Fast and memory-efficient regular expression matching for deep packet inspection [ C ]// ANCS '06: Proceedings of the 2006 IEEE/ACM Symposium on Architectures for Networking and Communications Systems. New York: ACM, 2006: 93- 102.
  • 10蔡良伟,程璐,李军,李霞.基于遗传算法的正则表达式规则分组优化[J].深圳大学学报(理工版),2015,32(3):281-289. 被引量:4

二级参考文献159

共引文献119

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部