节点文献
基于ECA规则的入侵检测研究
Study of Intrusion Detection Based on ECA Rule
【摘要】 入侵检测系统一般只对入侵行为所引起的事件或系统特征进行分析,而往往忽略了入侵事件间的关联特征,以及入侵事件和系统状态间的联系。文章将ECA规则引入到入侵检测系统中,同时对系统动态特性和静态特性进行了分析,从而提高入侵检测的能力。
【Abstract】 Currently, the intrusion detection system only analyzes system signature or events resulted by intrusion behavior. But it ignores theconjunction among intrusion events and the relation between intrusion event and system state. The ECA rules are applied to IDS in this paper. Whendynamic characteristic and static characteristic are analyzed at the same time, the capability of IDS is greatly improved.
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2005年16期
- 【分类号】TP393.08
- 【被引频次】5
- 【下载频次】117