New approach to evaluate the capacity of signature-based intrusion detection systems
|更新时间:2024-10-14
|
New approach to evaluate the capacity of signature-based intrusion detection systems
Issue 11, Pages: 6-14(2007)
作者机构:
1. 东南大学计算机科学与工程系
2. 东南大学计算机科学与工程系,江苏,南京,210096
3. 扬州大学信息工程学院
4. ,江苏,扬州,225000
作者简介:
基金信息:
DOI:
CLC:TP393.08
Published:2007
稿件说明:
移动端阅览
SUN Mei-feng1, GONG Jian1, YANG Wang1. New approach to evaluate the capacity of signature-based intrusion detection systems[J]. 2007, (11): 6-14.
DOI:
SUN Mei-feng1, GONG Jian1, YANG Wang1. New approach to evaluate the capacity of signature-based intrusion detection systems[J]. 2007, (11): 6-14.DOI:
New approach to evaluate the capacity of signature-based intrusion detection systems
摘要
为了提高评估的准确性
对基于特征的IDS的检测原理进行分析
提出分别评估规则库质量和IDS系统能力的原则。给出评估IDS系统能力的方法
该方法把人工知识视为评估参数
因此结论反映IDS实现的质量。重点讨论系统能力的测度定义
并简单介绍测度计算的总体思路。实验结果表明该方法更能反映基于特征的IDS的真实质量。
Abstract
For improving the accuracy of IDS evaluation
after the detection method of signature-based IDS was analyzed
pointed out that the current methods are not reasonable
and proposed the principle to evaluate the capability of IDS im-plementation and the capability of rule base respectively.The method to evaluate the capability of IDS implementation
which views the human knowledge as parameters
was introduced.The definition of metrics and how to calculate the value of metrics are mainly discussed.A prototype was implemented which shows that this new method can evaluate the real capacity better for a signature-based IDS.