基于模式匹配算法的协议分析入侵检测系统
Protocol Analysis Intrusion Detection System based on Multi-pattern Matching Algorithm
本文给出了一种基于模式匹配算法的协议分析入侵检测系统,将改进的模式匹配算法与协议分析相结合应用在入侵检测系统中, 应用该方法,构造网络入侵检测系统体系结构的主要模块有:数据包获取模块、协议解析模块、存储模块、检测模块、响应模块和界面管理模块。各模块之间既相互独立,又相互协作,共同完成对入侵检测行为的检测和处理。该系统中, 采用 WinPcap 来实现链路层数据捕获, 采用内存映射技术来提高数据包捕获效率;应用改进后的模式匹配算法, 提高模式匹配的速度, 减少比较的次数。这样的体系设计可以减少计算量, 提高算法的效率, 并通过协议分类减少不必要的误报率。提高了入侵检测系统的效率。
In this paper,a protocol analysis intrusion detection system based on multi-pattern matching algorithm is given.The improved pattern matching algorithm with a combination of protocol analysis used in intrusion detection systems. Application of this method, we construct the architecture of Network Intrusion Detection System .The main modules are: packet capture module, protocol analysis module, memory module, detection module, response module and interface management module. Both between the various modules are independent of each other and cooperate together to complete the act of intrusion detection to detect and deal with.In this system , the WinPcap is used to capture the networkpacket and the MMAP is used to improve efficiency ,the improved pattern matching algorithm is used to improve rates , and reduce times of comparing , the design of the system can greatly reduce the computation , improve efficiency of algorithm , and reduce the unnecessary misinformation rates by protocol .That will improve the efficiency of intrusion detection system.
郑鹏、曹彦燕
通信电子技术应用计算技术、计算机技术
入侵检测模式匹配协议分析
Intrusion detectionPattern patchingProtocol analysis
郑鹏,曹彦燕.基于模式匹配算法的协议分析入侵检测系统[EB/OL].(2009-03-03)[2025-08-11].http://www.paper.edu.cn/releasepaper/content/200903-36.点此复制
评论