SUN Mei-feng1, GONG Jian1, YANG Wang1. New approach to evaluate the capacity of signature-based intrusion detection systems[J]. 2007, (11): 6-14.DOI:
基于特征的入侵检测系统的评估新方法
摘要
为了提高评估的准确性
对基于特征的IDS的检测原理进行分析
提出分别评估规则库质量和IDS系统能力的原则。给出评估IDS系统能力的方法
该方法把人工知识视为评估参数
因此结论反映IDS实现的质量。重点讨论系统能力的测度定义
并简单介绍测度计算的总体思路。实验结果表明该方法更能反映基于特征的IDS的真实质量。
Abstract
For improving the accuracy of IDS evaluation
after the detection method of signature-based IDS was analyzed
pointed out that the current methods are not reasonable
and proposed the principle to evaluate the capability of IDS im-plementation and the capability of rule base respectively.The method to evaluate the capability of IDS implementation
which views the human knowledge as parameters
was introduced.The definition of metrics and how to calculate the value of metrics are mainly discussed.A prototype was implemented which shows that this new method can evaluate the real capacity better for a signature-based IDS.