首页> 外文OA文献 >Acquisition of evidence from network intrusion detection systems
【2h】

Acquisition of evidence from network intrusion detection systems

机译:从网络入侵检测系统获取证据

摘要

The literature reviewed suggests that Network Intrusion Systems (NIDS) are valuable tools for the detection of malicious behaviour in network environments. NIDS provide alerts and the trigger for rapid responses to attacks. Our previous research had shown that NIDS performance in wireless networks had a wide variation under different workloads. In this research we chose wired networks and asked the question: What is the evidential value of NIDS? Three different NIDS were tested under two different attacks and with six different packet rates. The results were alarming. As the work loading increased the NIDS detection capability fell rapidly and as the complexity of attack increased the NIDS detection capability fell more quickly. We conclude that NIDS have weak evidential value for either system improvement or legal admissibility.
机译:回顾的文献表明,网络入侵系统(NIDS)是检测网络环境中恶意行为的有价值的工具。 NIDS提供警报和触发器,以快速响应攻击。我们之前的研究表明,在不同工作负载下,NIDS在无线网络中的性能差异很大。在这项研究中,我们选择了有线网络并提出了以下问题:NIDS的证据价值是什么?三种不同的NIDS在两种不同的攻击下以六种不同的包速率进行了测试。结果令人震惊。随着工作量的增加,NIDS的检测能力迅速下降,并且随着攻击的复杂性增加,NIDS的检测能力下降得更快。我们得出的结论是,NIDS对于系统改进或法律可接受性而言,证据价值不高。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号