首页 | 本学科首页   官方微博 | 高级检索  
     

提高Snort规则匹配速度的研究
引用本文:刘棣华,苏春芳,董添.提高Snort规则匹配速度的研究[J].计算机工程与设计,2007,28(14):3344-3346.
作者姓名:刘棣华  苏春芳  董添
作者单位:长春工业大学计算机科学与工程学院 吉林长春130012(刘棣华,苏春芳),吉林大学通讯工程学院 吉林长春130012(董添)
基金项目:吉林省科技厅科技发展计划
摘    要:Snort是一种基于规则匹配的误用入侵检测系统,基于规则的模式匹配是Snort检测引擎的主要机制,也是衡量其性能的重要指标.由于当前Snort采用的规则树结构过于简单,造成某些RTN下的OTN链比较庞大;匹配过程中,OTN各个选项的匹配顺序仍然局限于安全专家根据领域知识,人为而定,从而造成某些重要选项不能得到优先匹配,大大降低了Snort的匹配速度,严重影响检测效率.为解决上述问题,将数据挖掘技术应用到Snort入侵检测系统中,利用数据挖掘中的ID3算法,对Snort规则库中的规则进行挖掘,选取信息增益最大的属性作为Snort优先匹配的属性,从而提高了规则匹配的速度.

关 键 词:入侵检测系统  规则树  ID3算法  信息熵  信息增益  Snort  规则库  匹配速度  研究  speed  increasing  属性  信息增益  选取  数据挖掘  算法  利用  入侵  技术应用  问题  检测效率  影响  严重  领域知识  专家
文章编号:1000-7024(2007)14-3344-03
修稿时间:2006-07-12

Research on increasing speed of rule-matching in snort
LIU Di-hua,SU Chun-fang,DONG Tian.Research on increasing speed of rule-matching in snort[J].Computer Engineering and Design,2007,28(14):3344-3346.
Authors:LIU Di-hua  SU Chun-fang  DONG Tian
Affiliation:1. College of Compute Science and Engineering, Changchun University of Technology, Changchun 130012, China; 2. College ofCommunicationEngineering, JilinUniversity, Changchun 130012, China
Abstract:Snort is an intrusion detection system based on rule-matching.Rule-matching is an important mechanism of Snort,and a index of its capacity.For the rule-tree of snort is so simple that there are a lot of OTNS behind RTN;the matching-sequence of items of OTN is decided by security experts,therefore some important items are not matched first.In a word,the mechanism of rule-matching decreases snort's detection capacity greatly.To resolve these issues,data-mining technology is used in Snort intrusion detection system,and ID3 algorithm is used to mine snort's rules to get some important attributes having highest information-gain.Searching first in detec-tion process of snort,consequently the detection speed of snort is increased.
Keywords:intrusion detection system  rule-tree  ID3 algorithm  information-entropy  information-gain
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号