期刊文献+

基于网络状态的入侵行为描述及存储方法 被引量:1

Network state based on intrusion action describe and storage method
在线阅读 下载PDF
导出
摘要 提出了一种基于正则语言描述的网络状态入侵行为方法。该方法结合网络入侵的目标和特点,利用有穷自动机理论,基于网络协议来实现进程和操作系统的状态建立,从而可以发现未知的入侵。论证了应用该方法的可行性,利用通用入侵检测框架CIDF对应用这种方法的入侵检测系统进行了描述,并讨论了该系统实现时攻击描述的判断和存储方式,最后与其它入侵行为方法进行了比较。 First, a network state intrusion action method based positive language describing was presented. This method is established by using DFA theory, characters and goals of net-attacks and fully depending on states of the processes of net protocols and operation system, so it could discover unknown attacks. It was proved that the method was feasible for intrusion detection and described IDS that using this model to describe net-attacks by CIDF (Common Intrusion Detection Framework). Then the method's storage and implement were discussed. In the end, the method was compared with other intrusion detection descriptions.
出处 《计算机工程与设计》 CSCD 北大核心 2006年第3期453-456,共4页 Computer Engineering and Design
关键词 入侵行为 有穷自动机 网络状态 通用入侵检测框架 存储 intrusion action DFA networks tare CIDF storage
  • 相关文献

参考文献8

  • 1.MEMCO白皮书SessionWall-3网络保护和入侵探测产品SessionWall-3技术概览[EB/OL].http://www.cooltang.com/box/topic/character/program/nsfocus/107.htm,1999.
  • 2Stevens W Richard.TCP/IP Illustrated Volume l:The protocols[M].Addison Wesley Press,1994.
  • 3Lee W,Stolfo S J,Mok K.A data mining framework for building intrusion detection models[C].Proceedings of the IEEE Symposium on Security and Privacy,1999.
  • 4Tim Bass.Multisensor data fusion for next generation distributed intrusion detection systems[C].Iris National Symposium Draft,1999.
  • 5Abdelaziz Mounji.Rule-based distributed intrusin detection[R].Namur Belgium Institut d'Informatique University of Namur rue Grandgagnage 21,1997.
  • 6Koral Llgun,Richard A Kemmerer.State transition annlysis:A rule-based intrusion detection approach[J].IEEE Transactions on Software Engineering,1995,21(3):181-199.
  • 7Giovanni Vigna,Richard A.Netstat:A network-based intrusion detection system[J].Journal of Computer Security,1999,7(1):37-71.
  • 8SHAN Zheng.A network state based intrusion detection model[C].IEEE ICCNMC'01,IEEE Computer Society Press,2001.

同被引文献5

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部