节点文献

入侵检测系统的可信性及其改进策略研究

Research on credibility and its improved policy for intrusion detection system

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 陆阳郑孝遥鲍红杰

【Author】 LU Yang,ZHENG Xiao-yao,BAO Hong-jie(College of Computer and Information,Hefei University of Technology,Hefei 230009,China)

【机构】 合肥工业大学计算机与信息学院合肥工业大学计算机与信息学院 安徽合肥230009安徽合肥230009

【摘要】 入侵检测系统在网络安全中有重要的作用,但是入侵检测系统的可信性问题一直没有很好解决,成为困扰入侵检测技术发展的一个主要因素。因此,为了改善入侵检测系统的可信性,给出了可信度的数学定义,阐明了可信度和虚警率、漏警率及检测率的关系;分析了产生虚警的原因。以Snort系统为仿真对象,提出了系统的改进结构、关联性分析模块和报警分析器,并对报警分析的3种方法进行了说明;最后介绍了系统的仿真测试和数据分析结果。

【Abstract】 Intrusion detection system is very important in network security.But the credibility of intrusion detection system has not been solved properly.So it becomes a primary problem that impedes the development of intrusion detection technology.In order to improve the credibility of intrusion detection system,the mathematical definition of degree of credibility is given,and the relationship between the false alarm rate,missing alarm rate,detection rate and the degree of credibility is illuminated.Reasons of false alarm are analyzed too.By using Snort as a simulation object,an improved architecture of system,an interrelation module and an alarm analysis module is proposed.Furthermore,three methods in the alarm analysis module are explained.Lastly,the result of simulation test and data analysis are introduced.

【基金】 安徽省自然科学基金项目(00043115)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2007年01期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】181
节点文献中: 

本文链接的文献网络图示:

本文的引文网络