论文部分内容阅读
针对基于签名的网络入侵检测系统(NIDS)中计算负荷较大的问题,提出一种利用简化粒子群优化(SSO)的自适应黑名单分组过滤器网络入侵检测方法,使用SSO 加权搜索分析来自路由器和入侵检测系统(IDS)攻击包的攻击模式和规则,在监视引擎中计算信任IP 并以自适应方式生成黑名单,基于自适应黑名单分组过滤器周期性地更新黑名单,使得黑名单分组过滤器可以自适应过滤网络分组.实验结果表明提出的方法可以在不降低网络安全性的前提下,有效减轻基于签名的NIDS 的计算负担.“,”Netuork intrusion detection systems (NIDS) According to the problem of large load calculation for network intrusion detection system (NIDS) based on signature, the adaptive blacklist packet filter network intrusion detection method by simplified suarm optimization (SSO) is proposed, using SSO weighted search analysis from the router and the intrusion detection system (IDS) mode of attack packets, and computing trust IP in the monitoring engine and generating a blacklist in an adaptive way. updates the blacklist based on the adaptive blacklist packet filter periodically, so that the blacklist packet filter can adaptively filter network packet. The experimental results show that the proposed method can effectively reduce the computational burden of signature based NIDS without reducing the network security.