节点文献
基于审计的入侵检测系统
Audit-based Intrusion Detection System
【摘要】 大多数操作系统、数据库系统及应用系统都提供了某种审计机制,但通常情况下审计信息仅被作为一种事后的证据。这样便浪费了这些对于保障信息系统安全具有重大意义的宝贵资源。因此,将审计跟踪与入侵检测结合起来,实现基于主机的实时入侵检测是非常有意义的。分析了审计跟踪遇到的问题及基本原理,探讨了基于审计的入侵检测系统的目标及关键技术。
【Abstract】 Most existing operating systems, database systems and application systems provide certain auditing mechanisms. However, audit information is only used as an after-the-fact evidence. This wastes the valuable resource which is very important for computer security. To combine audit trail with intrusion detection is very helpful for security monitoring. This paper discusses the goal and the key technique about audit-based and intrusion detection system.
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2000年S1期
- 【分类号】TP393.08
- 【被引频次】17
- 【下载频次】178