节点文献
面向网络加密流量的增量式入侵检测关键技术研究综述
Review of Key Technologies of Incremental Intrusion Detection for Network Encrypted Traffic
【摘要】 在网络空间安全威胁持续加剧的当下,加密流量攻击的隐蔽性与零日漏洞利用的突发性,致使传统入侵检测系统在动态网络环境中检测效能显著衰减。本文首先系统构建面向加密流量的增量式入侵检测技术分析框架,从技术协同视角出发,详细阐释各关键技术在增量式入侵检测中的协同逻辑与关联机制;随后聚焦当前研究前沿,分别从加密流量数据约简、加密恶意流量识别、未知加密恶意流量检测以及入侵检测模型的增量更新等4个关键技术领域展开深度研究和探索,并对比分析各类方法的优缺点;最后阐述面向加密流量的增量式入侵检测研究的未来发展趋势和面临的挑战。
【Abstract】 As cyber threats continue to intensify, the concealment of encrypted traffic attacks and the suddenness of zero-day exploits have significantly reduced the detection efficiency of traditional intrusion detection systems. This review systematically constructs an incremental intrusion detection technology analysis framework for encrypted traffic and explains the synergy and correlation mechanisms of key technologies in incremental intrusion detection from a synergistic technology perspective. Focusing on current research frontiers, in-depth research and exploration are conducted in four key technical fields: encrypted traffic data reduction, encrypted malicious traffic identification, unknown encrypted malicious traffic detection, and incremental updates of intrusion detection models. The advantages and disadvantages of various methods are analyzed. Finally, future development trends and challenges are discussed.
【Key words】 incremental intrusion detection; encrypted traffic data reduction; encrypted malicious traffic identification; unknown encrypted malicious traffic detection; incremental update of detection models;
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2025年12期
- 【分类号】TP393.08
- 【下载频次】106