节点文献

MAIDS-多检测技术的IDS模型

MAIDS-Model of IDS with Multi-Technology

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 田俊峰张喆赵卫东

【Author】 Tian Junfeng Zhang Zhe Zhao Weidong (College of Mathematics and Computer,Hebei University,Baoding,Hebei 071002)

【机构】 河北大学数学与计算机学院河北大学数学与计算机学院 河北保定071002河北保定071002

【摘要】 目前,入侵检测系统的漏报率和误报率高一直是困扰IDS用户的主要问题,而入侵检测系统主要有误用型和异常型两种检测技术。针对这一问题,根据这两种检测技术各自的优点,以及它们的互补性,将两种检测技术结合起来的方案越来越多地应用于IDS中。论文提出了基于统计的异常检测技术和基于模式匹配的误用检测技术及其它检测技术相结合的IDS模型-MAIDS,以期达到减少入侵检测系统的漏报率和误报率的目的,从而提高系统的安全性。

【Abstract】 Currently,the false positive and the false negative of Intrusion Detection System are very high.It is always the main problem that bothers the user of IDS.But there are two main technologies applied in IDS.To this problem,because both the technologies have its own advantages and they can supply for each other.So IDS combined with the two technologies is used more and more widely.This paper presents a model of IDS based on combination of Misuse Detection,Anomaly Detection and other detection technologies called MAIDS.In this model,Misuse Detection is based on pattern matching and Anomaly Detection is based on statistical analysis.It combines the two technologies to reduce the false positive rate and the false negative rate,and then to improve security of IDS.

【基金】 河北省自然科学基金资助项目(编号:F2004000133)
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2006年05期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】69
节点文献中: 

本文链接的文献网络图示:

本文的引文网络