首页> 外国专利> APPARATUS FOR MEASURING SIMILARITY BETWEEN INTRUSION DETECTION RULES AND METHOD THEREFOR

APPARATUS FOR MEASURING SIMILARITY BETWEEN INTRUSION DETECTION RULES AND METHOD THEREFOR

机译:用于测量入侵检测规则之间的相似性的方法及其方法

摘要

The present invention relates to an apparatus and method that check similarity between intrusion detection rules used by an Intrusion Detection System. The apparatus for measuring similarity between intrusion detection rules includes a normalization unit for modifying a plurality of detection rules in a predetermined form, a division unit for dividing each of detection rules among a plurality of modified detection rules into a detection rule header and a detection rule option, a relationship operation unit for determining an inclusion relationship between a detection rule headers, and determining an inclusion relationship between a detection rule options, and a similarity measurement unit for measuring similarity between the detection rules based on the inclusion relationship between the detection rule headers and the inclusion relationship between the detection rule options.
机译:本发明涉及一种检查由入侵检测系统使用的入侵检测规则之间的相似性的装置和方法。用于测量入侵检测规则之间的相似性的设备包括:标准化单元,用于以预定形式修改多个检测规则;划分单元,用于将多个修改后的检测规则当中的每个检测规则划分为检测规则头和检测规则。选项,关系操作单元,用于确定检测规则头之间的包含关系,并确定检测规则选项之间的包含关系;以及相似度测量单元,用于基于检测规则头之间的包含关系来测量检测规则之间的相似度以及检测规则选项之间的包含关系。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号