计算机与现代化 ›› 2010, Vol. 1 ›› Issue (10): 170-173.doi: 10.3969/j.issn.1006-2475.2010.10.046

• 信息安全 • 上一篇    下一篇

一种基于协议分析和免疫原理的网络入侵检测模型

耿俊成,牛霜霞,莫坚松   

  1. 河南电力试验研究院,河南 郑州 450052
  • 收稿日期:2010-04-20 修回日期:1900-01-01 出版日期:2010-10-21 发布日期:2010-10-21

A Network Intrusion Detection Model Based on Protocol Analysis and Immunological Principle

GENG Jun-cheng, NIU Shuang-xia, MO Jian-song   

  1. Henan Electric Power Research Institute, Zhengzhou 450052, China
  • Received:2010-04-20 Revised:1900-01-01 Online:2010-10-21 Published:2010-10-21

摘要: 通过对协议分析技术和生物免疫系统的理论分析,本文提出一种新的基于协议分析和免疫原理的网络入侵检测模型。该模型对检测器集合按照协议类型分类,生成相应的检测器子集,并设计一种新的检测器结构,对检测器进一步分类。每个子集中检测器独自进行变异、进化,整个检测器集合以子集为单位进行更新。在实际检测中,待检模式与相应的检测器子集匹配,从而能有效地提高检测速度,改进以往模型在这方面的不足。

关键词: 入侵检测, 免疫原理, 协议分析, 检测器子集

Abstract: With theoretical analysis of protocol analysis and biological immunity system, this paper presents a new intrusion detection model based on protocol analysis and immunological principle. The model can sort the set of detectors according to the protocol type, and generate the relevant subsets of the detectors. Designing a new detector structure can sort the detectors further. The detectors of each subset can mutate, evolve alone and the whole detectors update based on subset. In practical detection, the patterns to be detected match the relevant subset of the detectors, so the detection speed can be effectively improved, making up the deficiency of past modes.

Key words: intrusion detection, immune theory, protocol analysis, subset of detectors

中图分类号: