首页> 外文会议>Information security applications. >Rule Indexing for Efficient Intrusion Detection Systems
【24h】

Rule Indexing for Efficient Intrusion Detection Systems

机译:高效入侵检测系统的规则索引

获取原文
获取原文并翻译 | 示例

摘要

As the use of the Internet has increased tremendously, the network traffic involved in malicious activities has also grown significantly. To detect and classify such malicious activities, Snort, the open-sourced network intru sion detection system, is widely used. Snort examines incoming packets with all Snort rules to detect potential malicious packets. Because the portion of mali cious packets is usually small, it is not efficient to examine incoming packets with all Snort rules. In this paper, we apply two indexing methods to Snort rules, Prefix Indexing and Random Indexing, to reduce the number of rules to be examined. We also present experimental results with the indexing methods.
机译:随着Internet的使用急剧增加,恶意活动所涉及的网络流量也大大增加。为了检测和分类此类恶意活动,广泛使用开放源代码网络入侵检测系统Snort。 Snort使用所有Snort规则检查传入的数据包,以检测潜在的恶意数据包。由于恶意数据包的部分通常很小,因此使用所有Snort规则检查传入数据包效率不高。在本文中,我们将两种索引方法应用于Snort规则,即前缀索引和随机索引,以减少要检查的规则数量。我们还介绍了索引方法的实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号