论文部分内容阅读
当今的网络攻击事件频繁发生,用户严重受到来自黑客攻击的威胁。因此为了出于保护用户的需要,网络安全人员不得不开发出多种网络安全措施。目前网络的安全设备主要有防火墙和入侵检测系统。入侵检测系统中有两种检测方法误用检测算法和异常检测算法。本文在参考了已有的误用检测算法后,提出了一种新的检测算法。该算法将某些智能性算法融入了其中。本文中首先通过计算未知程序的权值,通过权值的属性来判断该程序是恶意程序还是合法的程序,如果某种程序属于恶意程序,则再使用MMTD的算法对恶意程序的大小属性进行匹配,最后通过已知恶意程序的属性有未知程序属性的比较,最终来判断该网络攻击程序属于何种攻击手段。最后说明一点,本文提出的算法主要是针对变体攻击手段进行检测。
Today’s cyber attacks occur frequently and users are severely threatened by hacking. Therefore, in order to protect the needs of users, cyber security personnel have to develop a variety of network security measures. The current network security equipment mainly firewall and intrusion detection system. There are two detection methods intrusion detection system misuse detection algorithm and anomaly detection algorithm. After referring to the existing misuse detection algorithm, this paper proposes a new detection algorithm. The algorithm incorporates some intelligent algorithms into it. In this paper, we first calculate the weights of unknown programs and judge whether the program is a malicious program or a legal program by using the attributes of the weights. If a program is a malicious program, then the MMTD algorithm is used to match the size and properties of the malicious programs Finally, by comparing the attributes of unknown malicious programs with unknown program attributes, we can finally determine which attack methods the attack program belongs to. Lastly, we point out that the algorithm proposed in this paper is mainly for detecting variant attacks.