作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (9): 164-166. doi: 10.3969/j.issn.1000-3428.2008.09.059

• 安全技术 • 上一篇    下一篇

一种混合式网络入侵检测系统

孙 云,黄 皓   

  1. (南京大学软件新技术国家重点实验室,南京 210093)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-05-05 发布日期:2008-05-05

Hybrid Network Intrusion Detection System

SUN Yun, HUANG Hao   

  1. (National Laboratory for Novel Software Technology, Nanjing University, Nanjing 210093)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-05-05 Published:2008-05-05

摘要: 入侵检测系统通常采用单一的检测模式,难以有效地处理漏报和误报问题。该文分析不同类型网络流量的分布特征,提出一种将异常检测和误用检测相结合的混合式网络入侵检测系统,从总体上克服了单一模式的不足。实验结果表明,该方法能有效地提高入侵检测系统的检测率和准确率。

关键词: 入侵检测, 异常检测, 误用检测, 混合式入侵检测

Abstract: Intrusion Detection System(IDS) has been harassed by false positive and false negative problem. Common IDS using single detection mode is hard to solve this problem effectively. This paper analyzes the characteristics of network flow and presents a new method, called hybrid IDS, combining misuse detection mode and anomaly detection mode, the method can overcome the shortcomings of IDS using single mode. Experiments show that the new method can improve IDS detection rate and decrease false alerts effectively.

Key words: intrusion detection, anomaly detection, misuse detection, hybrid intrusion detection

中图分类号: