节点文献
基于动态规则的IPv6入侵检测系统研究
Research of IPv6 IDS based on Dynamic rule
【摘要】 本文在分析snort规则检测及Snort入侵检测系统工作原理的基础上,结合IPv6协议本身的特点及其安全性,提出一种IPv6动态规则匹配机制,通过增加选项索引链表,对规则匹配的次序进行动态调整,实现了一个快速高效的IPv6入侵检测系统。实验表明,该系统可有效地检测IPv6各种攻击,平均每包检测速度提高了约12.53%。
【Abstract】 Based on the analysis of Snort’s rule and the princIPle of instruction detection system for snort,combined with the char-acteristic and security mechanisms of IPv6,this paper puts forward a dynamic rule-matching mechanism for IPv6. In order to adjust the sequence of rule-matching dynamically,it adds a chain of the option index. It carries out the quickness and efficiency of the in-struction detection system for IPv6. The experiment shows that the system not only detects kinds of attacking for IPv6,but improves detection speed about 12.53%.
【基金】 河南省自然科学基金项目(0611054800);河南省科技攻关计划项目(0623051200)
- 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2008年12期
- 【分类号】TP393.08
- 【被引频次】6
- 【下载频次】154