节点文献
基于模式匹配的网络入侵检测系统研究
The Research of Intrusion Detection System Based on Pattern Matching
【作者】 张雷;
【导师】 何大可;
【作者基本信息】 西南交通大学 , 密码学, 2005, 硕士
【摘要】 随着网络的普及和快速发展,网络用户面临着日益严重的安全问题,网络入侵已经成为计算机安全和网络安全的最大威胁。应运而生的网络入侵检测成为当前的研究重点和热点。 本论文对入侵检测研究现状进行了分析和总结,重点研究了网络入侵检测的核心技术—模式匹配,并提出了入侵检测技术面临的问题和研究发展趋势。 首先,本文概述了入侵检测系统的模式、组成、分类和研发趋势,然后重点对模式匹配算法,如BF,KMP,BM等算法从原理到性能等进行了详细的分析和讨论,在此基础上,提出了对BM算法的两种改进算法。改进算法与标准BM算法相比,在比较次数上有一定的减少,在时间性能上有所提高。同时,本文也提出了一种基于字符出现概率进行优先匹配的方法。 本文接下来讨论了一种新的检测技术—协议分析。通过对模式匹配和协议分析的比较,本文得出了当前NIDS有必要整合这两种检测方法的结论。 最后,本文分析了入侵检测面临的问题,展望了IDS的发展远景。
【Abstract】 With the popularization and fast development, network users face increasingly serious security issues, thus network intrusion has become the most important threat to the computer security and network security. So network intrusion detection system(NIDS) appears as the keystone and hotspot in the computer security research field which emerge as the times require.This dissertation analyses and summarizes the current status of intrusion detection research, focuses on research and practice on pattern matching algorithm which is technique difficulties in network intrusion detection ,proposes some problems intrusion detection technology must face and research trend.First, this dissertation summarizes model, constitutes, category and trend of IDS, and then pattern matching which is applied widely is discussed in detail from the aspect of theory and technology principle and performance of mostly pattern match algorithm such as BF, KMP and BM. This paper bring two forth modified algorithms for BM. These improved algorithms reduce comparison number and improve time performance contrasted with the standard BM algorithm. The paper also brings a new pattern matching method which is based on the frequency of character appearing.The paper also discusses a new intrusion detection technology: protocol analysis. Through contrasted of pattern match and protocol analysis, It gets a conclusion that integrating these two methods into NIDS is necessary for current NIDS.At last, this dissertation analyses some problems intrusion detection technical must face and discusses expectation of IDS in future.
【Key words】 network security; network intrusion detection system(NIDS); pattern matching algorithm; protocol analysis;
- 【网络出版投稿人】 西南交通大学 【网络出版年期】2005年 06期
- 【分类号】TP393.08
- 【被引频次】19
- 【下载频次】294