节点文献

入侵检测系统中的协议分析子系统的设计和实现

Design and Implementation of Protocol Analysis Sub-system in Intrusion Detection System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 李佳静徐辉潘爱民

【Author】 Li Jiajing Xu Hui Pan Aimin(The Computer Science Institute,Peking University,Beijing100871)

【机构】 北京大学计算机科学研究所文字信息处理国家重点实验室北京大学计算机科学研究所文字信息处理国家重点实验室 北京100871北京100871北京100871

【摘要】 对于一个网络入侵检测系统,协议分析主要有三方面的作用:为检测引擎提供输入,提高检测的有效性,提高检测效率。对于这些功能,该文论述的协议分析子系统对应有三个功能模块:基本协议数据解析模块,包括对数据包各个头部字段的解析;上下文相关的数据关联模块,包括IP分片合并和TCP会话重组;应用层协议分析模块,包括对常见应用协议数据的关键字段的提取和分析。文章的最后给出了系统的应用层协议分析的性能测试数据。

【Abstract】 Protocol analysis sub-system in intrusion detection system has three important functions:supplying data to detection engine,improving the effectivity of detection and improving the efficiency of detection.According to these functions,the protocol analysis sub -system described in this paper implements three modules:basic protocol parsing module,including parsing the header fields of a packet;context analysis module,including recombinating IP fragments and reconstructing TCP sessions;application protocols analysis module,including abstracting keyword from application protocol messages.The test result of application protocols analysis module is provided in the last paragraph.

【基金】 国家863高技术研究发展计划项目基金资助(项目号:863-301-06-03)
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2003年12期
  • 【分类号】TP393.08
  • 【被引频次】56
  • 【下载频次】233
节点文献中: 

本文链接的文献网络图示:

本文的引文网络