计算机科学 ›› 2013, Vol. 40 ›› Issue (12): 174-176.

• 网络与通信 • 上一篇    下一篇

改进BM算法及其在网络入侵检测中的应用

孙文静,钱华   

  1. 南京理工大学 南京210094;南京联迪信息系统有限公司 南京210019
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家发改委发改办[2012]3179号下一代互联网络扫描与补丁管理系统产业化项目基金资助

Improved BM Algorithm and Its Application in Network Intrusion Detection

SUN Wen-jing and QIAN Hua   

  • Online:2018-11-16 Published:2018-11-16

摘要: 传统BM算法存在一些无用的比较,影响了字符串的匹配速度,降低了入侵检测效率。为此,提出一种改进BM算法,并将其用于网络入侵检测系统的检测引擎中。实验结果表明,较采用BM算法的Snort检测器,改进BM算法构建的网络入侵检测系统可有效降低误报率和漏报率,提高入侵检测率与时间利用率。显然,这对提升网络入侵检测系统的整体能力非常有用。

关键词: 入侵检测,改进BM算法,检测效率,误报率与漏报率

Abstract: The traditional BM algorithm has some useless comparison,affecting the string matching speed and reducing the efficiency of intrusion detection.Therefore,this paper proposed an improved BM algorithm,applied it to the engine of network intrusion detection system.Experimental results show that,compared with BM algorithm which employs Snort detection, a network intrusion detection system constructed by improved BM algorithm can effectively reduce the false positive rate and false negative rate,and improve intrusion detection rate and time utilization.Obviously,this network intrusion detection system is very useful for enhancing the overall capacity.

Key words: Intrusion detection,Improved BM algorithm,Detection efficiency,False positive rate and false negative rate

[1] Boyer R S,Moore J S.A fast string searching algorithm [J].Communications of the ACM,1977,20(10):762-772
[2] 李洋,王康,谢萍.BM模式匹配改进算法[J].计算机应用研究,2004,21(4):58-59
[3] 杨薇薇,廖翔.一种改进的BM模式匹配算法[J].计算机应用,2006,26(2):318-319
[4] Roesch M.Snort:Lightweight Intrusion Detection for Networks[C]∥ LISA’ 99Proceedings of the 13th USENIX Conference on System Administration.1999:229-238
[5] http://www.ll.mit.edu/IST/
[6] 魏旻,王一帆,李玉, 等.基于WIA-PA网络的周界入侵检测系统设计与实现[J].重庆邮电大学学报:自然科学版,2013,5(2):148-153

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!