Dissertation > Excellent graduate degree dissertation topics show
The Research Method of Pattern Matching and Protocol Analysis in Intrusion Detection System
Author: WangTongJun
Tutor: WangJie
School: Zhengzhou University
Course: Control Theory and Control Engineering
Keywords: Intrusion Detection Network Security Pattern Matching Protocol Analysis Boyer-Moore Algorithm
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 30
Quote: 0
Read: Download Dissertation
Abstract
|
With the rapid development of computer technology and network data communication technology, the computer information and network security have become important issue. As the speed of detection technique is low and veracity of detection is not high, which occupies more resource of the system. Intrusion detection technology which is based on the pattern matching has been unable to meet the needs of intrusion detection. Protocol analysis can rapid detection the no safety factor of network based on highly regular of network protocol. The technique based on protocol analysis is extremely popular, it not only can reduce rate of missing alarm and failing alarm, but also has advantage of reduce usage of resource of the system.Pattern matching is an important part of the intrusion detection system, that it directly affects the overall performance of the system. First, this paper emphatically analyzes several common pattern matching algorithms in intrusion detection system. In the research of classical pattern matching algorithm—Boyer-Moore algorithm, this paper puts an improved Boyer-Moore algorithm on the basis of combine with the advantages of Boyer-Moore-Horspool algorithm and Boyer-Moore-Horspool-Sunday algorithm. Boyer-Moore algorithm has a large preprocessing time overhead, pointing to this disadvantage. The new algorithm can increase the pattern strings matching speed efficiently through reducing the times of moving pattern strings and increasing the times of the furthest moving distance m +1 appears, it reduce the time and improve the efficiency of the pattern matching. Secondly, in the basis of comprehensive analysis the characteristics of pattern matching and protocol analysis, this paper proposes an intrusion detecting system based on improved pattern matching and protocol analysis to solve the vast computing amounts and a high false positive rate of the pattern matching technology. The system put effective combination of pattern matching and protocol analysis, and can take full advantage of highly regular of network protocol to detect the existence of the known and unknown vulnerabilities and attack. In the process of detection, through layered analysis of network data based on define standardization and hierarchical, format network protocol, it not only can improve the accuracy and speed of detection, but also effectively control rate of missing alarm and failing alarm. In conclusion, the author summarizes the research and pointed out the next phase of the research.
|
Related Dissertations
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- Region-based wireless sensor network key management scheme for research,TP212.9
- SX Provincial Public Security Bureau Network Security Corps Performance Evaluation Index System Design,D631.1
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Ship mountain of e-government network security solutions outside the network design and implementation,TP393.08
- Firewall and three switch - based campus network security policy research,TP393.08
- Research and Design of Secure Comunication of NVD on Demand System,TP309
- Fast protocol identification based firewall system design and implementation,TP393.08
- Automated Fuzz Testing network protocol vulnerabilities mining method,TP393.08
- Intrusion detection based on data mining technology research,TP393.08
- The Research and Application of Support Vector Machine in Intrusion Detection System,TP393.08
- High Speed Deep Packet Inspection Algorithm Research Based on Hardware Support,TP393.08
- Research on P2P Flow Identification Using Behavior Characteristics,TP393.02
- Research and Implementation on Access Control for Intranet Terminal Based on Policy,TP393.08
- Research on High-Speed IP Packet Capture Technology Based on Multi-core Architecture,TP393.08
- Stream-based protocol to determine methods research,TP393.08
- Design and Implementation of the campus network security management system,TP393.18
- Network intrusion detection technology in data mining algorithm,TP393.08
- Research on Fusion Technology of Multi-source Log Secure Information,TP393.08
- Windows Kernel Rootkit Detection Technology Research,TP309
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|