摘要
入侵检测系统是近年来发展迅速的一种网络安全技术。但是,随着计算机网络向着高速、宽带的方向发展,检测引擎越来越成为性能的瓶颈。如果检测速度不能跟上网络流量,就会丢包并发生漏报。这除了采用更高速的专业硬件来解决外,包过滤算法也有非常重要的作用。高速的过滤算法有助于过滤掉大量无关的信息,从而极大地提高入侵检测系统的性能。
Intrusion detection system is a rapidly developed network security technology. But as network has developed toward rapid speed and broadband, detect engine becomes a performance bottleneck. If network is overload, IDS will lose attack messages. So packet filter algorithms are very important to solve this problem. A good algorithm can filter much no useful message and improve IDS's performance.
出处
《计算机工程》
CAS
CSCD
北大核心
2003年第16期109-110,共2页
Computer Engineering