节点文献

一种混合式入侵检测系统

A Hybrid Intrusion Detection System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 彭建刘凯

【Author】 PENG Jian LIU Kai(College of Computer & Communication Engineering,Changsha University of Science & Technology,Changsha 410114,China)

【机构】 长沙理工大学计算机与通信工程学院

【摘要】 针对现有入侵检测系统采用单一检测模式难以有效地解决漏报和误报问题,本文从开源软件snort系统开始分析,提出一种混合式入侵检测系统SHIDS(A Serial Hybrid Intrusion Detection System),将两种不同检测模式相结合,较好解决单一检测模式不足,同时对未知病毒也进行了预判。实验结果显示,SHIDS比误用检测系统漏报率低,检测速率较快;比异常检测误报率低,解释性也较强。

【Abstract】 For existing intrusion detection system using a single test mode is difficult to tackle the issue of omission and misstatement,this paper proposed a new SHIDS(Serial Hybrid Intrusion Detection System).We start from the open source software SNORT and then combines two different detect pattern together.The result shows that SHIDS has covers the shortage of single test mode while unknown viruses have also been pre-judgment:1) SHIDS has a lower omission rate and a faster detection speed 2) SHIDS has a lower misstatement rate and a higher explanatory.

  • 【文献出处】 微计算机信息 ,Microcomputer Information , 编辑部邮箱 ,2012年01期
  • 【分类号】TP393.08
  • 【下载频次】62
节点文献中: 

本文链接的文献网络图示:

本文的引文网络