首页> 外文期刊>International Journal of Information Security >IDSIC: an intrusion detection system with identification capability
【24h】

IDSIC: an intrusion detection system with identification capability

机译:IDSIC:具有识别功能的入侵检测系统

获取原文
获取原文并翻译 | 示例
           

摘要

Security is an important but challenging issue in current network environments. With the growth of Internet, application systems in enterprises may suffer from new security threats caused by external intruders. This situation results in the introduction of security auditors (SAs) who perform some test methods with hacking tools the same as or similar to those used by hackers. However, current intrusion detection systems (IDSs) do not consider the role of security auditors despite its importance. This causes IDSs to generate many annoying alarms. In this paper, we are motivated to extend a current IDS functionality with Identification Capability, called IDSIC, based on the auditing viewpoint to separate auditing traffic from malicious attacks. The IDSIC architecture includes two components: fingerprint adder and fingerprint checker, which can provide a separability of security auditors and hackers. With this architecture, we show that IDSICs can lower the consequential costs in the current IDSs. Therefore, such IDSICs can ensure a more stable system performance during the security examination process.
机译:在当前的网络环境中,安全性是重要但具有挑战性的问题。随着Internet的增长,企业中的应用系统可能会遭受外部入侵者带来的新安全威胁。这种情况导致引入了安全审计员(SA),他们使用与黑客使用的工具相同或相似的黑客工具执行某些测试方法。但是,当前的入侵检测系统(IDS)尽管很重要,但并未考虑安全审核员的作用。这导致IDS生成许多烦人的警报。在本文中,我们有动机基于审计观点来扩展当前具有标识能力的IDS功能(称为IDSIC),以将审计流量与恶意攻击分开。 IDSIC体系结构包括两个组件:指纹加法器和指纹检查器,它们可以提供安全性审核程序和黑客的可分离性。通过这种架构,我们证明IDSIC可以降低当前IDS的相应成本。因此,此类IDSIC可以在安全检查过程中确保更稳定的系统性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号