首页 | 本学科首页   官方微博 | 高级检索  
     

基于用户可信度的误用入侵检测系统的研究
引用本文:郭庆北,张华忠,丁秀明.基于用户可信度的误用入侵检测系统的研究[J].计算机应用,2006,26(5):1081-1083.
作者姓名:郭庆北  张华忠  丁秀明
作者单位:山东大学,计算机科学与技术学院,山东,济南,250100;济南大学,信息科学与工程学院,山东,济南,250022;山东大学,计算机科学与技术学院,山东,济南,250100;江南大学,信息工程学院,江苏,无锡,214036
摘    要:提出了基于用户可信度的误用IDS模型,该模型对IDS框架结构、签名匹配策略及协同机制都进行了改进。鉴于通用入侵检测框架CIDF(Common Intrusion Detection Framework)结构中缺少对入侵等级划分的机制,提出了基于用户可信度量化的等级划分方法,提高了系统的合理性。定义了误用IDS安全级别,通过预警原理实现低安全级别IDS对未知入侵的预防作用。另外,在用户可信度IDS中使用了局部性原理,进而改善了签名匹配策略并提高了签名的匹配效率和准确率。

关 键 词:用户可信度  局部性原理  预警  自动响应
文章编号:1001-9081(2006)05-1081-03
收稿时间:2005-11-21
修稿时间:2005-11-212006-03-01

Misuse intrusion detection system based on user trust degree
GUO Qing-bei,ZHANG Hua-zhong,DING Xiu-ming.Misuse intrusion detection system based on user trust degree[J].journal of Computer Applications,2006,26(5):1081-1083.
Authors:GUO Qing-bei  ZHANG Hua-zhong  DING Xiu-ming
Affiliation:1. School of Computer Science and Technology, Shandong University, Jinan Shandong 250100, China; 2. School of Information Science and Engineering, Jinan University, Jinan Shandong 250022, China; 3. College of Information Engineering, Southern Yangtze University, Wuxi Jiangsu 214036, China
Abstract:In this paper, a misuse detection model for IDS based on user trust degree (UTD) was firstly presented. This model improves the architecture of IDS, the strategy of signature matching, and the cooperation mechanism. UTD-IDS presents a means of graded partition that based on UTD whereas there is a lack of graded partition in the architecture of CIDF, so it improves the rationality of the system. The safety level of misuse IDS was defined and the IDS of lower safety level may prevent unknown intrusion from damage by the early-alert principle. In addition, was reformed full advantage of local principle were taken in UTD-IDS, then the strategy of signature matching, so it improves the efficiency and accuracy of signature matching.
Keywords:user trust degree  local principle  early-alert  automation response
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号