作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (09): 142-144.

• 安全技术 • 上一篇    下一篇

入侵检测系统的数据标准化应用研究

叶和平1,2,尚 敏1,范路桥1,2   

  1. (1. 广东科学技术职业学院软件工程系,广州 510640;2. 华南理工大学计算机学院,广州 510640)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-05-05 发布日期:2007-05-05

Study on Data Standardlization Application in Intrusion Detection System

YE Heping1,2, SHANG Min1, FAN Luqiao1,2   

  1. (1. Dept. of Software Engin., Guandong Vocational Institute of Science and Technology, Guangzhou 510640; 2. Dept. of Computer Science and Engin., South China Univ. of Tech., Guangzhou 510640)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-05-05 Published:2007-05-05

摘要: 在分析入侵检测系统原理及通用入侵检测框架(CIDF)的基础上,按照CIDF的结构要求,设计了基于CIDF的入侵检测系统原型。在系统实现的内部机制上,采用链表的形式保存各类事件的完整信息并按CIDF的要求进行检测数据的标准化,为系统构件共享信息提供高效、准确的保证。结合实践,指出了用语义标识符SID扩充以适应异常检测方面的问题。

关键词: 入侵检测, 通用入侵检测对象, 通用入侵检测框架, 数据标准化

Abstract: This paper gives an introduction to the principle of intrusion detection, explanins what is CIDF and why CIDF is needed. Based on these material, it designs a model for intrusion detection according to CIDF. To give the model high performance, it uses chains in memory to save the information of all events occurred in running time and standardlize data from the these events. In the end, it put forwards some points about expanding SID and some SIDs applied in anomaly detection.

Key words: Intrusion detection, Generalized intrusion objects(GIDO), Common intrusion detection frame(CIDF), Data standardlization

中图分类号: