摘要
回顾了计算机网络入侵检测系统发展的过程,从入侵检测系统的类型划分这个角度,描述了基于主机和基于网络两种数据源、基于滥用和基于异常两种检测方法,并对各自的优缺点进行了比较。从体系结构、数据源和数据分析技术三个方面对入侵检测系统的当前研究现状进行了详细的论述。最后,对入侵检测系统的未来发展方向进行了讨论。
An overview of IDS's historical development is presented. After that, host-based IDS and network-based IDS are discussed and misuse detection and anomaly detection are compared.A review of architectures, data sources and data analysis techniques of IDS is given. Finally, the IDS in the future are predicted.
出处
《计算机测量与控制》
CSCD
2004年第4期301-304,共4页
Computer Measurement &Control