首页> 外文会议>2012 12th International Conference on Intelligent Systems Design and Applications. >BSnort IPS Better Snort Intrusion Detection / Prevention System
【24h】

BSnort IPS Better Snort Intrusion Detection / Prevention System

机译:BSnort IPS更好的Snort入侵检测/预防系统

获取原文
获取原文并翻译 | 示例

摘要

With the advent of a range of intrusion detection and prevention systems out in the market and Snort IPS standing out from others, always there have been efforts to improve upon the current scenario. Here, a novel technique that can curb many of the current Denial-of-Service attacks which usually disrupts the network connectivity by consuming a large amount of bandwidth is discussed. The Better Snort Intrusion Detection/Prevention System (BSnort) uses Aho-Corasick automaton for the deep packet inspection and makes use of the modified Snort signatures which utilizes minimum amount of CPU and memory. The BSnort stands out from other Network Intrusion Detection Systems (NIDSs) in its integrated use of anomaly detection approach to find out novel attacks using the packet header along with the use of known attack signatures for the payload to pin-point intrusions.
机译:随着市场上各种入侵检测和防御系统的出现以及Snort IPS脱颖而出,一直在努力改进当前情况。在这里,讨论了一种新颖的技术,该技术可以遏制许多当前的拒绝服务攻击,这些攻击通常通过消耗大量带宽来破坏网络连接。更好的Snort入侵检测/防御系统(BSnort)使用Aho-Corasick自动机进行深度数据包检查,并使用经过修改的Snort签名,该签名使用了最少的CPU和内存。 BSnort在其他网络入侵检测系统(NIDSs)的综合使用中脱颖而出,它使用异常检测方法来发现新颖的攻击,该攻击使用数据包报头,并使用有效载荷的已知攻击签名来精确定位入侵。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号