首页 | 本学科首页   官方微博 | 高级检索  
     

基于异常和特征的入侵检测系统模型
引用本文:Frans David,王建新,王斌.基于异常和特征的入侵检测系统模型[J].计算技术与自动化,2004,23(3):19-22.
作者姓名:Frans David  王建新  王斌
作者单位:中南大学,信息科学与工程学院,湖南,长沙,410083
摘    要:目前大多数入侵检测系统(Intrusion Detection System,IDS)没有兼备检测已知和未知入侵的能力,甚至不能检测已知入侵的微小变异,效率较低。本文提出了一种结合异常和特征检测技术的IDS。使用单一技术的IDS存在严重的缺点,为提高其效率,唯一的解决方案是两者的结合,即基于异常和特征的入侵检测。异常检测能发现未知入侵,而基于特征的检测能发现已知入侵,结合两者而成的基于异常和特征的入侵检测系统不但能检测已知和未知的入侵,而且能更新基于特征检测的数据库,因而具有很高的效率。

关 键 词:IDS  基于特征  入侵检测系统模型  特征检测  异常检测  数据库  解决方案  严重  发现  变异
文章编号:1003-6199(2004)03-0019-04
修稿时间:2004年3月17日

An Anomaly & Signature-based Intrusion Detection System Model
Frans David,WANG Jian-xin,WANG Bin.An Anomaly & Signature-based Intrusion Detection System Model[J].Computing Technology and Automation,2004,23(3):19-22.
Authors:Frans David  WANG Jian-xin  WANG Bin
Abstract:Most intrusion detection systems (IDS) today lack the ability to detect both known and unknown intrusions. Even a very slight variation from known intrusions will go undetected thus rendering the IDS ineffectiveness. This paper proposes Anomaly and Signature-based Intrusion Detection System. The combination is needed in order to increase effectiveness of the IDS. The need arouse due to the fact that individual detection systems possesses serious drawbacks which can be solved only by combining them. With this at hand gives rise to an approach known as anomaly signature-based which is more efficient than individual techniques. This is due to the fact that anomaly detection detects unknown intrusions while signature-based detection detects known intrusions. By combining both techniques in conjunction with our anomaly signature-based system approach we are assured of an intrusion detection system that does not only detect both known and unknown intrusions but also capable of updating the signature-based detection database, thus in return rendering effectiveness to intrusion detection systems.
Keywords:Anomaly detection  Anomaly and signature-based intrusion detection system  
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号