节点文献

基于语法分析树的入侵检测技术

Intrusion detection technology based on parsing tree

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 贾存虎仇德成李大伟徐德启

【Author】 JIA Cun-hu1,2,QIU De-cheng2,3,LI Da-wei2,XU De-qi2(1.Jiuquan’s Satellite Launching Center,Jiuquan 735000,China;2.School of Information Science and Engineering,Lanzhou University,Lanzhou 730000,China;3.Department of Computer,Hexi University,Zhangye 734000,China)

【机构】 酒泉卫星发射中心兰州大学信息科学与工程学院河西学院计算机系

【摘要】 对系统入侵的状态转换进行了研究,分析了常见的黑客攻击方法,包括TCPSYNFLOODING、IP分片攻击等。针对现有入侵检测技术的不足,构建了一个新的入侵检测模式,提出了基于特征信息序列语法分析的入侵检测技术。实现多种入侵用统一的文法描述,有效地避免了检测分析中的盲目试探,提高了检测效率。由于采用了可扩展的文法创建技术,使其具备一定的异常检测能力,能识别未知的入侵或攻击。

【Abstract】 At first,researching the state conversion of system intrusion,analyzing some famous attacking methods,such as TCP SYN FLOODING,IP FRAGMENT OVERLAP and so on,according to defect of the existing intrusion detection technology,a new intrusion detection model is accomplished,intrusion detection technology based on characteristic information sequence parsing is proposed.It can realize that a variety of network or system intrusion will be described the same pattern,can avoid blindness of the probing,the ef-ficiency of detection will be improved greatly.As scalability of the grammar creating technology,the intrusion detection system is made to be certain anomaly detection capabilities,can recognition unknown intrusion or attack.

  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2009年18期
  • 【分类号】TP393.08
  • 【下载频次】98
节点文献中: 

本文链接的文献网络图示:

本文的引文网络