摘要
通过对Snort入侵检测系统的测试,发现该系统针对135、1434端口和IIS_Translate_F漏洞攻击未能进行报警。根据入侵检测规则文件的语法规则,编写出针对漏报情况的新的入侵检测规则文件,从而使得入侵检测系统的检测成功率明显提高,有效的降低了漏报率。
Through the testing of Snort-Based intrusion detection system, we find that the system can not warn based on the port 135, 1434 and the omission IIS_Translate_F striking. According to intrusion detective grammatical rules, write the new intrusion detective rules, thereby to increase efficiency of the intrusion detective system apparently and reduce the underreport rates.
出处
《微计算机信息》
2011年第2期156-157,共2页
Control & Automation
关键词
SNORT
入侵检测系统
规则
漏报率
Snort
Intrusion detection system
Rules
Underreported rate