【24h】

Using automatic signature generation as a sensor backend

机译:使用自动签名生成作为传感器后端

获取原文

摘要

The techniques and supporting tools for signature based intrusion detection have reached a high level of maturity. They are well understood by the community and have hardware implementations capable of matching rules at high speed. Their major shortcomings involve handling "zero-day" attacks. Anomaly or protocol-adherence based sensors are capable of detecting zero-day attacks, but with high false alarm rates and at more limited speeds. The design proposed here combines the zero-day detection capabilities already supplied by anomaly detection front ends with the speed, hardware compatability and mature infrastructure of signature based systems. A unique capability of this proposed technology is that false alarm rates of matched rules can be reduced to arbitrarily low levels by increasing the amount of training on benign traffic. A goal of future work would be to produce an efficient and secure mechanism to distribute automatically generated signatures with the goal of broadening the perimeter of protection and blocking attacks farther away from sensitive servers and hosts.
机译:基于签名的入侵检测技术和支持工具已经达到很高的成熟度。它们被社区很好地理解,并且具有能够高速匹配规则的硬件实现。它们的主要缺点涉及处理“零时差”攻击。基于异常或基于协议的传感器能​​够检测零时差攻击,但误报率高且速度受限。这里提出的设计将异常检测前端已经提供的零日检测功能与基于签名的系统的速度,硬件兼容性和成熟的基础架构结合在一起。此提议技术的独特功能是,通过增加对良性流量的训练量,可以将匹配规则的虚警率降低到任意低的水平。未来工作的目标是提供一种有效且安全的机制来分发自动生成的签名,以扩大保护范围并阻止更远离敏感服务器和主机的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号