摘要
由于缺乏对网络主机上下文的了解,多数基于特征的NIDS(网络入侵检测系统)产生的虚警数量太多,使得管理员无法尽快将注意力集中到真正有威胁的报警上。通过改进已有的NIDS使其能够有效利用网络主机上的软件信息消除NIDS虚警的有效方法,改进后的NIDS根据已知的受监控网段内的主机软件信息,在与入侵规则做匹配之前进行预先判断,过滤掉不需要匹配的入侵规则,从而减少很多没有实际意义的报警记录。改进后的NIDS原型系统在企业内部网实施的实测结果显示,该方法确实可以达到减少虚警数量提高报警质量的目的。
For lackness of knowledge about the context of network hosts, most signature-based NIDSs produce too many false positives, which prevent the administrators from focusing their efforts on real dangerous alerts quickly. A mechanism in NIDS is proposed, which makes a decision before pattern matching to filter unnecessary intrusion rules for matching, by utilizing the sottware information of the target hosts, to mitigate false positives drastically. This method is implemented in the prototype system. The result of testing on typical intranet shows that this method surely mitigate false positives and improve quality of alerts in NIDS.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第3期538-541,共4页
Computer Engineering and Design
基金
浙江省科研基金项目(2004201)
浙江省科学技术厅基金项目