摘要
滥用检测(misusedetection)是两大主要的入侵检测方法之一,它虽然对已知入侵的检测成效显著,但对其变种攻击,就无能为力。鉴于此,该论文提出了一个新的滥用检测方案,它不但能对已知入侵本身准确识别,而且对其变种,也能尽可能地予以识别,并确认出变种与原种入侵之间的差异。
Misuse detection is one of both intrusion detection methods.Despite of excellent effect on known intrusions,it holds futile on their variations.Therefore,this paper provides a new scheme for misuse detection,which not only can recognize known intrusions accurately,but also can recognize their variations as far as possible and confirm discrepancy between original intrusions and their variations.
出处
《计算机工程与应用》
CSCD
北大核心
2003年第36期163-165,共3页
Computer Engineering and Applications