作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (11): 120-122. doi: 10.3969/j.issn.1000-3428.2009.11.040

• 安全技术 • 上一篇    下一篇

Snort规则链表结构的改进与仿真

(山西大学计算机与信息技术学院,太原 030006)   

  1. (山西大学计算机与信息技术学院,太原 030006)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-06-05 发布日期:2009-06-05

Improvement and Simulation of Snort Rule Chains Structure

SUN Min, GU Xiao-ming, ZHANG Zhi-li   

  1. (School of Computer & Information Technology, Shanxi University, Taiyuan 030006)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-06-05 Published:2009-06-05

摘要: Snort系统根据规则链表对捕获的数据包进行匹配,以发现攻击行为,规则链表结构的合理性在很大程度上影响检测速度。针对Snort规则链表结构中局部聚集的现象,对其按共性选项因式分解,将规则按所含选项的信息量进一步排序。在仿真平台OPNET上的模拟结果表明,改进后的规则链表结构能减少规则匹配时间。

关键词: 误用入侵检测, 规则链表, 因式分解, 网络仿真

Abstract: For finding attacks, Snort matches the captured packets with rule chains, therefore the rationality of the rule chains influences the detection speed of Snort greatly. This paper factors out common options from the rule chains, for solving the problem of local accumulation. It sorts the rules according to information quantity of the options. Simulation results of the OPNET shows that the improved rule chains structure can reduce the time of rules matching.

Key words: misuse intrusion detection, rule chains, factoring, network simulation

中图分类号: