期刊文献+

基于Snort的入侵检测系统性能优化 被引量:3

The Performance Optimization of Snort-based Intrusion Detection System
在线阅读 下载PDF
导出
摘要 通过对Snort的规则匹配方式和模式匹配算法进行分析,为了提高基于Snort的入侵检测系统检测效率,提出了在规则匹配过程中充分利用处理函数的参数之间的关系,从而动态减少无效匹配次数,在模式匹配阶段采用改进的模式匹配算法提高匹配速度,从根本上优化了入侵检测系统的检测性能。 Snort is a mature open source code network invasion detection system. The rule matching mode and pattern matching arithmetic have been analyzed in this paper. For improve the speed of the snort--based intrusion detection, we utilized relationship between parameters, significantly reduced invalid rules in the running time. By using the improved pattern matching arithmetic to increase the matching speed in the pattern matching phase, the detection performance was optimized ultimately.
作者 韩忠秋
出处 《计算机安全》 2009年第6期41-43,共3页 Network & Computer Security
关键词 入侵检测系统 规则匹配 模式匹配 性能优化 intrusion detection system rule matching pattern matching performance optimization
  • 相关文献

参考文献2

二级参考文献8

  • 1孙振龙,宋广军,李晓晔,黄迎春.基于数据挖掘技术的Snort入侵检测系统的研究[J].微计算机信息,2006,22(11X):212-214. 被引量:9
  • 2Roesch M.Snort-lightweight Intrusion Detection for Networks[Z].http://www.snort.org/docs/lisapaper.txt,2003-02-20.
  • 3Roesch M,Green C.Snort Users Manual[Z].http://www.snort.org,2004-08-11.
  • 4Coit J C,Staniford S,McAlerney J.Towards Faster String Matching for Intrusion Detection[C].Proc.of DARPA Information Survivability Conference and Exposition,2001:367-373.
  • 5Norton M,Roelker D.Hi-performance Multi-rule Inspection Engine[Z].http://www.snort.org,2004-04.
  • 6INSKI A C-. A synchronization, Algorithm for processes with dynamic priorities in computer networks with node failures[J]. Information Processing Letters, 1989 , 32(3) : 129-136
  • 7INSKIA Two Algorithms for Mutual Exclusion in. Real-time Distributed Computer Systems[J]. Journal of Parallel and Distributed Computing, 1990,9(1) : 77-82
  • 8CASWELLBrian, BEALEJay, FOSTERJamesC, et al. Snort2.0 intrusion detection[M].北京:国防工业出版社,2004

共引文献18

同被引文献20

引证文献3

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部