Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2008, Vol. 34 ›› Issue (9): 164-166. doi: 10.3969/j.issn.1000-3428.2008.09.059

• Security Technology • Previous Articles     Next Articles

Hybrid Network Intrusion Detection System

SUN Yun, HUANG Hao   

  1. (National Laboratory for Novel Software Technology, Nanjing University, Nanjing 210093)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-05-05 Published:2008-05-05

一种混合式网络入侵检测系统

孙 云,黄 皓   

  1. (南京大学软件新技术国家重点实验室,南京 210093)

Abstract: Intrusion Detection System(IDS) has been harassed by false positive and false negative problem. Common IDS using single detection mode is hard to solve this problem effectively. This paper analyzes the characteristics of network flow and presents a new method, called hybrid IDS, combining misuse detection mode and anomaly detection mode, the method can overcome the shortcomings of IDS using single mode. Experiments show that the new method can improve IDS detection rate and decrease false alerts effectively.

Key words: intrusion detection, anomaly detection, misuse detection, hybrid intrusion detection

摘要: 入侵检测系统通常采用单一的检测模式,难以有效地处理漏报和误报问题。该文分析不同类型网络流量的分布特征,提出一种将异常检测和误用检测相结合的混合式网络入侵检测系统,从总体上克服了单一模式的不足。实验结果表明,该方法能有效地提高入侵检测系统的检测率和准确率。

关键词: 入侵检测, 异常检测, 误用检测, 混合式入侵检测

CLC Number: