节点文献
Snort入侵检测系统中TCP流重组的研究
Research On TCP reassembly in Snort IDS
【摘要】 文章通过分析Snort入侵检测系统的源代码,剖析了snort入侵检测系统的TCP流重组的原理及实现,给出了相关数据结构和算法流程,介绍了针对流重组模块的攻击及Snort对此的防御策略,最后指出现有TCP流重组技术几点不足及若干新的研究方向。
【Abstract】 Base on the study on the source code of Snort, analyze the principle and implementation of TCP assembly in Snort IDS, present related data structures and arithmetic. Introduce attacks that towards TCP assembly module and the protection methods Snort adopted. Indicate several weaknesses of TCP assembly and some new research fields of it.
【关键词】 TCP重组;
Snort;
Hash表;
Splay树;
入侵检测;
【Key words】 TCP reassembly; Snort; Hash table; Splay tree; Intrusion detection;
【Key words】 TCP reassembly; Snort; Hash table; Splay tree; Intrusion detection;
- 【文献出处】 信息安全与通信保密 ,China Information Security , 编辑部邮箱 ,2007年02期
- 【分类号】TP393.08
- 【被引频次】18
- 【下载频次】500