首页> 外文OA文献 >From Intrusion Detection to Intrusion Detection and Diagnosis: An Ontology-Based Approach
【2h】

From Intrusion Detection to Intrusion Detection and Diagnosis: An Ontology-Based Approach

机译:从入侵检测到入侵检测与诊断:一种基于本体的方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Currently available products only provide some support in terms of Intrusion Prevention and Intrusion Detection, but they very much lack Intrusion Diagnosis features. We discuss the limitations of current Intrusion Detection System (IDS) technology, and propose a novel approach - which we call Intrusion Detection & Diagnosis System (ID2S) technology - to overcome such limitations. The basic idea is to collect information at several architectural levels, using multiple security probes, which are deployed as a distributed architecture, to perform sophisticated correlation analysis of intrusion symptoms. This makes it possible to escalate from intrusion symptoms to the adjudged cause of the intrusion, and to assess the damage in individual system components. The process is driven by ontologies. We also present preliminary experimental results, providing evidence that our approach is effective against stealthy and non-vulnerability attacks.
机译:当前可用的产品仅在入侵防御和入侵检测方面提供了一些支持,但是它们非常缺乏入侵诊断功能。我们讨论了当前入侵检测系统(IDS)技术的局限性,并提出了一种新颖的方法-我们称之为入侵检测与诊断系统(ID2S)技术-来克服这种局限性。基本思想是使用部署为分布式体系结构的多个安全探针在几个体系结构级别上收集信息,以执行入侵症状的复杂关联分析。这样就可以从入侵症状升级到确定的入侵原因,并评估单个系统组件的损坏。该过程由本体驱动。我们还提供了初步的实验结果,提供了证据表明我们的方法可以有效地抵御隐形和非漏洞攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号