论文部分内容阅读
基于异常检测的入侵检测系统,能够发现未知的攻击,而如何定义“正常”的行为,是一个关键问题。提出了一个利用网络服务特征,进行异常检测的入侵检测系统,能够发现单个包中的恶意攻击。
An intrusion detection system based on anomaly detection can detect unknown attacks and how to define “normal” behavior is a key issue. An intrusion detection system using network service features for anomaly detection is proposed, which can detect malicious attacks in a single packet.