首页>
外国专利>
METHOD AND APPARATUS FOR GENERATING NETWORK INTRUSION DETECTION RULE
METHOD AND APPARATUS FOR GENERATING NETWORK INTRUSION DETECTION RULE
展开▼
机译:生成网络入侵检测规则的方法和装置
展开▼
页面导航
摘要
著录项
相似文献
摘要
The present invention relates to a method that, in order to automatically generate an intrusion detection rule used in a network intrusion detection system, when a set of existing intrusion detection rules, normal network traffic, suspicious network traffic, and a maximum intrusion detection rule length are given as inputs, filters out strings that are not included in the normal network traffic but are included only in the suspicious network traffic, calculates similarities between the filtered strings and the existing intrusion detection rules, and then selects the most similar intrusion detection rule to a new attack, thereby providing an intrusion detection rule candidate for the new attack by using the most similar intrusion detection rule.
展开▼