首页> 外国专利> An efficient method and device for generating network intrusion detection rules

An efficient method and device for generating network intrusion detection rules

机译:一种高效的网络入侵检测规则生成方法及装置

摘要

The present invention relates to a method of calculating, when a set of existing intrusion detection rules, normal network traffic, suspicious network traffic, and a maximum length of an intrusion detection rule are given as an input, similarity between character strings included in the suspicious network traffic, not included in the normal network traffic, and existing intrusion detection rules after filtering the character strings, selecting an intrusion detection rule most similar to a new attack, and providing candidates of an intrusion detection rule against the new attack using the selected intrusion detection rule, in order to automatically generate an intrusion detection rule used in a network intrusion detection system, and the method of generating an intrusion detection rule according to the present invention includes the steps of: selecting a character string suspected as an attack through a character string selection unit using a set of intrusion detection rules, normal network traffic, suspicious network traffic, and a maximum length of a new intrusion detection rule; comparing an existing intrusion detection rule with the character string suspected as an attack through a rule comparison unit; and generating a possible intrusion detection rule from the candidate rules sorted in accordance with similarity through a rule generation unit. The automatically generated intrusion detection rule according to the present invention has an effect of enhancing security performance of an intrusion detection system by rapidly generating an intrusion detection rule against a new attack without wasting time and effort of an expert.
机译:本发明涉及一种当输入一组现有的入侵检测规则,正常网络流量,可疑网络流量和入侵检测规则的最大长度作为输入时,计算可疑字符串中的相似度的方法。过滤字符串后,选择与新攻击最相似的入侵检测规则,并使用所选入侵针对新攻击提供入侵检测规则的候选者,然后过滤字符串,将不包括在正常网络流量中的网络流量和现有入侵检测规则检测规则,以便自动生成在网络入侵检测系统中使用的入侵检测规则,并且根据本发明的生成入侵检测规则的方法包括以下步骤:选择被怀疑通过字符攻击的字符串使用一组入侵检测规则的字符串选择单元,普通网工作流量,可疑网络流量以及新入侵检测规则的最大长度;通过规则比较单元将现有的入侵检测规则与怀疑为攻击的字符串进行比较;通过规则生成单元从根据相似度排序的候选规则中生成可能的入侵检测规则。根据本发明的自动生成的入侵检测规则具有通过快速生成针对新攻击的入侵检测规则而不会浪费专家的时间和精力来增强入侵检测系统的安全性能的效果。

著录项

  • 公开/公告号KR20180070247A

    专利类型

  • 公开/公告日2018-06-26

    原文格式PDF

  • 申请/专利权人 PATABI KOREA LTD.;

    申请/专利号KR20160172732

  • 发明设计人 PARK DONG KI;

    申请日2016-12-16

  • 分类号H04L29/06;

  • 国家 KR

  • 入库时间 2022-08-21 12:39:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号