【24h】

Application Level IDS using Protocol Analysis

机译:使用协议分析的应用级别ID

获取原文

摘要

As network attacks have increased in number and severity over the past few years, intrusion detection systems have become a necessary addition to the security infrastructure of most organizations. From a security perspective, firewalls and SSL offer little protection. Web traffic often contains attacks such as Cross-Site Scripting and SQL Injection that enter through Port 80 and are not blocked by the firewall. Among the web applications HTTP holds the majority share of the traffic transported through web. In this paper, implementation of an application level IDS has been presented which uses combination of pattern matching and protocol analysis approaches. The first method of detection relies on a multi pattern matching within the protocol fields, the second one provides an efficient decision tree adaptive to the application traffic characteristics to limit the number of patterns to be checked. The proposed IDS can be effectively implemented in a high performance semantic processor.
机译:随着过去几年的网络攻击增加数量和严重程度,入侵检测系统已成为大多数组织安全基础设施的必要补充。从安全透视,防火墙和SSL提供很少的保护。 Web流量通常包含攻击,例如通过端口80进入的跨站点脚本和SQL注入,并且不会被防火墙阻止。在Web应用程序中,HTTP持有通过Web传输的流量的大多数共享。在本文中,提出了应用级别ID的实现,其使用模式匹配和协议分析方法的组合。第一检测方法依赖于协议字段内的多模式匹配,第二个是为应用程序业务特性提供了一个有效的决策树,以限制要检查的模式的数量。所提出的ID可以在高性能语义处理器中有效地实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号