...
首页> 外文期刊>The Computer journal >A Digest and Pattern Matching-Based Intrusion Detection Engine
【24h】

A Digest and Pattern Matching-Based Intrusion Detection Engine

机译:基于摘要和模式匹配的入侵检测引擎

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection/prevention systems (IDSs/IPSs) heavily rely on signature databases and pattern matching (PM) techniques to identify network attacks. The engines of such systems often employ traditional PM algorithms to search for telltale patterns in network flows. The observations that real-world network traffic is largely legitimate and that telltales manifested by exploits rarely appear in network streams lead us to the proposal of Fingerprinter. This framework integrates fingerprinting and PM methods to rapidly distinguish well-behaved from malicious traffic. Fingerprinter produces concise digests or fingerprints for attack signatures during its programming phase. In its querying phase, the framework quickly identifies attack-free connections by transforming input traffic into its fingerprint space and matching its digest against those of attack signatures. If the legitimacy of a stream cannot be determined by fingerprints alone, our framework uses the Boyer-Moore algorithm to ascertain whether attack signatures appear in the stream. To reduce false matches, we resort to multiple fingerprinting techniques including Bloom-Filter and Rabin-Fingerprint. Experimentation with a prototype and a variety of traces has helped us establish that Fingerprinter significantlyrnaccelerates the attack detection process.
机译:入侵检测/防御系统(IDS / IPS)严重依赖签名数据库和模式匹配(PM)技术来识别网络攻击。这种系统的引擎通常采用传统的PM算法来搜索网络流中的讲述模式。现实世界中的网络流量在很大程度上是合法的,并且利用漏洞表现出来的故事很少出现在网络流中的观察结果使我们提出了Fingerprinter的建议。该框架集成了指纹识别和PM方法,以快速区分行为正常的恶意流量。指纹识别器会在其编程阶段为攻击特征生成简洁的摘要或指纹。在查询阶段,该框架通过将输入流量转换为指纹空间并将摘要与攻击特征进行匹配,从而快速识别无攻击的连接。如果流的合法性不能仅通过指纹来确定,我们的框架将使用Boyer-Moore算法来确定攻击签名是否出现在流中。为了减少错误匹配,我们采用了多种指纹技术,包括Bloom-Filter和Rabin-Fingerprint。对原型和各种痕迹进行的实验帮助我们确定了Fingerprinter大大加速了攻击检测过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号