• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2005, Vol. 27 ›› Issue (8): 13-15.

• 论文 • 上一篇    下一篇

一种基于入侵事件的检测分析技术

史亮 庄镇泉   

  • 出版日期:2005-08-01 发布日期:2010-07-03

  • Online:2005-08-01 Published:2010-07-03

摘要:

在本文中,我们针对目前入侵检测系统普遍存在的误报率高、报警信息冗余现象严重和对入侵表述能力不强的缺陷,提出了一种基于入侵事件的检测分析技术,详细描述了该 技术所采用主要方法的设计思想,如多传感器数据融合以及基于模糊规则的原始报警信息鉴别等。实验结果表明,同现有入侵检测系统相比,该技术大大降低了系统的检测成 成本。

关键词: 入侵检测 数据融合 模糊规则 入侵通报

Abstract:

In this paper, we present a detection technology based on intrusion events in order to overcome the shortcomings of high false alert rate, serious red  undant alerts and poor expression about the intrusion activities in today's intrusion detection systems. We describe the design ideas about the importa ant methods used in this technology such as multi-sensor data fusion, raw alert distinguishment based on fuzzy rules and so on in detail. Experimental r esults show that compared with the existing intrusion detection systems, this technology can reduce the system test cost greatly.

Key words: (intrusion detection, data fusion, fuzzy rule, intrusion report)