首页> 外文OA文献 >Analyzing pattern matching algorithms applied on snort intrusion detection system
【2h】

Analyzing pattern matching algorithms applied on snort intrusion detection system

机译:分析在Snort入侵检测系统中的模式匹配算法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Currently, intrusion detection system has become widely used as a network perimeter security. The used of IDS to prevent the extremely sophisticated attacks in most of our industries, governmental organization and educational institutions .However ,Intrusion detection system can be either host-based or network based intrusion detection system, in a host-base intrusion it monitors the host where its configured while the network-based IDS it monitors both inbound and outbound traffic network. Furthermore, signature based or anomaly based detection techniques are used to detect malicious packets or attack in both network and host-based intrusion detection systems. Therefore, the challenges faced by most of the signature based detection systems like Snort tool is incapability to detect malicious traffic at higher traffic network, which resulted in a packet drooping and subjected the network where this signature based system is configured as a network perimeter security. The challenges resulted as a result of inefficiency of the pattern matching algorithms to efficiently perform pattern matching. Moreover, this project research work aim to compare the current Boyer-Moore pattern matching algorithm applied by the snort IDS with the Quick Search pattern matching algorithm in order to evaluate their performance and recommend for the implementation of the new pattern matching algorithm that will enhance snort detection performance
机译:当前,入侵检测系统已被广泛用作网络边界安全。使用IDS可以防止我们大多数行业,政府组织和教育机构中极为复杂的攻击。但是,入侵检测系统可以是基于主机的入侵检测系统,也可以是基于网络的入侵检测系统,它可以在基于主机的入侵中监视主机。在基于网络的IDS时配置的位置,它同时监视入站流量和出站流量网络。此外,基于签名或基于异常的检测技术用于检测恶意数据包或基于网络和基于主机的入侵检测系统中的攻击。因此,大多数基于签名的检测系统(如Snort工具)面临的挑战是无法检测流量较高的网络上的恶意流量,这导致数据包下垂并使该基于签名的系统配置为网络外围安全性的网络受到攻击。这些挑战是由于模式匹配算法无法有效执行模式匹配而导致的。此外,该项目的研究工作旨在将snort IDS当前应用的Boyer-Moore模式匹配算法与Quick Search模式匹配算法进行比较,以评估其性能,并建议实施将增强snort的新模式匹配算法检测性能

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号