摘要
端口扫描检测是网络安全防御系统的重要组成部分,而分组抽样在高速主干网络中有着广泛的应用。论文分析了分组抽样给TRW检测方法造成影响的原因,提出了一种改进TRW算法,通过样本流中的TCP序列号信息改进原始流的流大小分布估计,降低了入侵检测的误检率。
Port scaning detection is an important part of network security system.Packed sample is largely used in high speed backbone network.Here we analyse the influence of packed sample on the TWR detecting method,then we propose an im proved method.It reduces the probability of incorrect detecting by the information of TCP sequence which improve distribu tion estimate of original stream.
出处
《电脑知识与技术(过刊)》
2012年第9X期6206-6210,6238,共6页
Computer Knowledge and Technology
关键词
分组抽样
端口扫描
入侵检测
packet sample
port Scanning
detection of invasion