...
首页> 外文期刊>International Journal of Security and Networks >Enhancing Intrusion Detection System with proximity information
【24h】

Enhancing Intrusion Detection System with proximity information

机译:利用邻近信息增强入侵检测系统

获取原文
获取原文并翻译 | 示例

摘要

Intrusion Detection Systems (IDSes) proposed to identify or prevent the wide spread of worms can be largely classified as signature-based or anomaly-based. Modern worms are often sufficiently intelligent to hide their activities and evade anomaly detection, rendering existing IDSes (particularly signature-based) less effective. We propose PAIDS, a proximity-assisted IDS approach for identifying the outbreak of unknown worms. Operating on an orthogonal dimension with existing IDSes, PAIDS can work collaboratively with existing IDSes for better performance. Trace-driven evaluation indicates that PAIDS has high detection rates and low false-positive rates. We also build a prototype with Google Maps APIs and libpcap library.
机译:提议用来识别或阻止蠕虫广泛传播的入侵检测系统(IDSes)大致可分为基于签名的或基于异常的。现代蠕虫通常具有足够的智能,可以隐藏其活动并逃避异常检测,从而使现有的IDS(尤其是基于签名的IDS)的效率降低。我们建议使用PAIDS,这是一种用于识别未知蠕虫爆发的邻近辅助IDS方法。 PAIDS可与现有IDS在正交维度上运行,可以与现有IDS协同工作以提高性能。痕量驱动的评估表明,PAIDS的检出率高,假阳性率低。我们还使用Google Maps API和libpcap库构建了一个原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号