首页 | 本学科首页   官方微博 | 高级检索  
     

入侵检测系统中报警验证模块的设计与实现
引用本文:左晶,段海新,于雪莉. 入侵检测系统中报警验证模块的设计与实现[J]. 计算机工程, 2008, 34(2): 267-269
作者姓名:左晶  段海新  于雪莉
作者单位:1. 清华大学电子工程系,北京,100084
2. 清华大学信息网络工程研究中心,北京,100084
基金项目:国家重点基础研究发展计划(973计划)
摘    要:传统入侵检测系统虽然可以根据特征匹配的方法检测出攻击企图,却无法验证攻击企图是否成功,生成的报警不仅数量巨大而且误警率很高。该文提出一种结合漏洞扫描工具对入侵检测系统生成的报警进行验证的方法,根据被攻击主机是否包含能使攻击成功的漏洞来判定攻击能否成功,对攻击的目标主机不存在对应漏洞的报警降低优先级,从而提高报警质量。说明了报警验证模型各部分的设计和实现方法,系统运行结果显示该方法能有效地压缩报警量,降低误警率,帮助管理员从大量数据中找到最应该关注的真实报警。

关 键 词:报警验证  入侵检测系统  网络安全
文章编号:1000-3428(2008)02-0267-03
收稿时间:2007-02-20
修稿时间:2007-02-20

Design and Implementation of Alert Verification Module in Intrusion Detection System
ZUO Jing,DUAN Hai-xin,YU Xue-li. Design and Implementation of Alert Verification Module in Intrusion Detection System[J]. Computer Engineering, 2008, 34(2): 267-269
Authors:ZUO Jing  DUAN Hai-xin  YU Xue-li
Affiliation:??1. Department of Electronic Engineering, Tsinghua University, Beijing 100084;
2. Research Center of Information Network Engineering, Tsinghua University, Beijing 100084??
Abstract:Traditional intrusion detection system detects intrusion attempts Using signature-based method, but it can hardly determine if the attempt is successful. As a result, alerts generated by IDS are not only huge in number but also poor in data quality, i.e. containing false positive alerts. This paper presents a method to verify alerts using vulnerability-scanning tools. The idea of alert verification is to check if the destination host has the necessary vulnerability that can make the intrusion successful. According to the result of alert verification process, attacks that possibly failed are degraded in priority. The experimental result shows that the alert verification model in distributed IDS can compress the duplicated alerts, reduce false positives efficientIy, which helps network administrators focus on actual alerts from overwhelming amount of data.
Keywords:alert verification  Intrusion Detection System(IDS)  network security
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机工程》浏览原始摘要信息
点击此处可从《计算机工程》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号