论文部分内容阅读
从系统安全方面分析了审计跟踪数据的特征及几种现行的入侵检测方法:用户特征简表法、入侵者特征简表法、签名分析、行为分析。最后介绍入侵检测专家系统(IDES)和Haystack系统,并给出了设计方法。
From the aspects of system security, this paper analyzes the characteristics of audit trail data and several current intrusion detection methods: user feature summary table, intruder profile table, signature analysis and behavior analysis. Finally, introduce IDES and Haystack system, and give the design method.