论文部分内容阅读
目前的入侵防御系统发展都较偏向特征型入侵防御系统,特征型的入侵防御系统利用特征比对的方式,当流量收集进入入侵防御系统之后,通过特征资料库比对后,来确定流量是否为非法的攻击入侵的流量,还是合法的流量。本文通过以流量统计信息、异常入侵防御系统事件信息与系统环境弱点知识库,设计一个基于多样信息的入侵防御系统,并建立入侵检测事件的分析机制,以提高检测准确度与降低误判率,并应用于实际的网络环境中收集网络存取信息,期望能够检测出真正威胁网络的异常特征,并减轻对管理者的负担。
At present, the development of intrusion prevention systems tends to be more characteristic eigenfacing intrusion prevention systems. The characteristic intrusion prevention system utilizes the characteristic comparison method. After the traffic is collected into the intrusion prevention system, the characteristics of the database are compared to determine whether the traffic is Illegal attacks on intruding traffic, or legal traffic. In this paper, an intrusion prevention system based on diversified information is designed based on traffic statistics, anomalous intrusion prevention system event information and system environment weakness knowledge base, and an intrusion detection event analysis mechanism is established to improve the detection accuracy and reduce the false positive rate. And used in the actual network environment to collect network access information, expect to be able to detect the real threat of network anomalies, and reduce the burden on managers.