节点文献
基于语法分析树的入侵检测技术
Intrusion detection technology based on parsing tree
【摘要】 对系统入侵的状态转换进行了研究,分析了常见的黑客攻击方法,包括TCPSYNFLOODING、IP分片攻击等。针对现有入侵检测技术的不足,构建了一个新的入侵检测模式,提出了基于特征信息序列语法分析的入侵检测技术。实现多种入侵用统一的文法描述,有效地避免了检测分析中的盲目试探,提高了检测效率。由于采用了可扩展的文法创建技术,使其具备一定的异常检测能力,能识别未知的入侵或攻击。
【Abstract】 At first,researching the state conversion of system intrusion,analyzing some famous attacking methods,such as TCP SYN FLOODING,IP FRAGMENT OVERLAP and so on,according to defect of the existing intrusion detection technology,a new intrusion detection model is accomplished,intrusion detection technology based on characteristic information sequence parsing is proposed.It can realize that a variety of network or system intrusion will be described the same pattern,can avoid blindness of the probing,the ef-ficiency of detection will be improved greatly.As scalability of the grammar creating technology,the intrusion detection system is made to be certain anomaly detection capabilities,can recognition unknown intrusion or attack.
【Key words】 attacking methods; intrusion detection; state conversion; sequence of characteristic information; parsing tree;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2009年18期
- 【分类号】TP393.08
- 【下载频次】98