节点文献

漏洞扫描和入侵检测联动机制探讨

The Correlation Mechanism of Vulnerability Scanner and Intrusion Detection System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王熠肖竟华

【Author】 WANG Yi, XIAO Jing-hua (School of Computer Science, Wuhan University of Science and Technology, Wuhan Hubei 430065,China)

【机构】 武汉科技大学计算机科学与技术学院

【摘要】 由于漏洞扫描器和入侵检测系统都有不同程度的产生误报和漏报的缺陷,提出了将这两个系统进行联动的模型和实现方案。该模型通过开放接口的方式实现联动,将漏洞信息和报警信息传递到联动机制中的预处理器,根据策略库的关联规则进行联动分析,可以很大程度上降低误报和漏报的比例,提高检测的效率。

【Abstract】 Both vulnerability scanner and intrusion detection system (IDS) suffer from the drawback of producing false positive and false negative results. So a correlation model between the vulnerability scanner and IDS is proposed in this paper. The model uses the open interface to implement correlation. First, the vulnerability information and alerts alarms are transmitted into the preprocessor; second, execute the correlation analysis according to the rules in policy database. This method can greatly reduce the false positive and false negative rates, enhancing the detection efficiency.

【关键词】 漏洞扫描入侵检测联动
【Key words】 vulnerability scanintrusion detectioncorrelation
  • 【文献出处】 计算机安全 ,Computer Security , 编辑部邮箱 ,2009年03期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】187
节点文献中: 

本文链接的文献网络图示:

本文的引文网络