首页> 外国专利> APPARATUS AND METHOD FOR IMPROVING DETECTION PERFORMANCE OF INTRUSION DETECTION SYSTEM

APPARATUS AND METHOD FOR IMPROVING DETECTION PERFORMANCE OF INTRUSION DETECTION SYSTEM

机译:改善入侵检测系统检测性能的装置和方法

摘要

An apparatus for improving detection performance of an intrusion detection system includes a transformed detected data generation unit for changing original detected data, detected based on current detection rules, to transformed detected data complying with transformed detected data standard. A transformed detected data classification unit classifies the transformed detected data by attack type, classifies transformed detected data for attack types by current detection rule, and classifies transformed detected data for detection rules into true positives/false positives. A transformed keyword tree generation unit generates a true positive transformed keyword tree and a false positive transformed keyword tree. A true positive path identification unit generates a true positive node, and identifies a true positive path connecting a base node to the true positive node in the true positive transformed keyword tree. A true positive detection pattern generation unit generates a true positive detection pattern based on the true positive path.
机译:一种用于提高入侵检测系统的检测性能的装置,包括:转换后的检测数据生成单元,用于将基于当前检测规则检测到的原始检测数据改变为符合转换后的检测数据标准的转换后的检测数据。变换后的检测数据分类单元按攻击类型对变换后的检测数据进行分类,按当前检测规则对攻击类型进行变换后的检测数据分类,并将检测规则的变换后检测到的数据分类为真阳性/假阳性。变换关键词树生成单元生成真正变换关键词树和假正变换关键词树。真实正路径识别单元生成真实正节点,并且在真实正变换关键字树中识别将基本节点连接到真实正节点的真实正路径。真实阳性检测图案生成单元基于真实阳性路径生成真实阳性检测图案。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号