论文部分内容阅读
基于特征的IDS为了检测到攻击,必须处理能与攻击表现相匹配的攻击描述,该过程可以简化为与网络报文部分匹配的模式描述,也可以复杂化为将多传感器输出映射到抽象攻击表现的状态机描述或神经网络描述。描述了入侵检测系统(IDS)中涉及的几个典型拒绝服务攻击(DoS)模式,对这些DoS攻击模式进行了详细的分析。DoS特征是书写检测特定攻击过滤器的必要知识,详细描述了这些DoS攻击的特征,并提出了抵御DoS攻击的一个应对措施———IDS。
Feature-based IDS In order to detect an attack, an attack description that matches the attack performance must be handled, which can be reduced to a pattern description that partially matches the network message and can also be complicated by mapping the multi-sensor output to abstract attack performance State machine description or neural network description. Describes several typical denial-of-service attacks (DoS) patterns involved in Intrusion Detection Systems (IDSs) and analyzes these DoS patterns in detail. DoS features are the necessary knowledge to write specific attack filters, describe the characteristics of these DoS attacks in detail, and propose a countermeasure against DoS attacks - IDS.