节点文献

网络入侵意图识别方法综述

A Survey on Network Intrusion Plan Recognition

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 宁卓龚俭

【Author】 NING Zhuo GONG Jian (Department of Computer Science and Technology,Southeast University,Nanjing 210096)

【机构】 东南大学计算机科学与工程系江苏省计算机网络技术重点实验室 南京210096

【摘要】 复合攻击的检测是近年来IDS着力解决的一个重要问题。研究表明,解决这个问题的根本途径在于建立有效的模型积累、识别多报文间的上下文关系,从而进一步对入侵的意图进行精确判断。本文跟踪了近年来意图识别领域的技术发展,详细介绍了几种有代表性方法的核心思想,分析它们适用的范围和存在的问题,比较了各自的优劣所在,最后总结了这个领域的难点问题和发展趋势。

【Abstract】 The detection of composed intrusion is an active topic for IDS now.The past researches have shown that in- trusion plan recognition technology is critical to reduce false or missed alert rate,tries to construct an effective model to accumulate the relationship among alerts in different context and promotes recognition accuracy.This paper summarizes the advantage and the shortcoming of the known intrusion plan recognition methods.The special requirements are dis- cussed and the most promising development is proposed.

【关键词】 复合入侵IDS意图识别警报关联
【Key words】 Composed intrusionIDSPlan recognitionEvent correlation
【基金】 国家973计划课题(2003CB314804);教育部科学技术重点研究项目(105084);江苏省网络与信息安全重点实验室(BM2003201)资助。
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年09期
  • 【分类号】TP393.08
  • 【被引频次】14
  • 【下载频次】327
节点文献中: 

本文链接的文献网络图示:

本文的引文网络