Dissertation > Excellent graduate degree dissertation topics show
Research and Implementation of Hybrid Intrusion Detection System Based on Snort
Author: LiWenLong
Tutor: QiaoPeiLi
School: Harbin University of Science and Technology
Course: Applied Computer Technology
Keywords: Intrusion Detection Snort system Data Mining Rule learning
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 57
Quote: 0
Read: Download Dissertation
Abstract
|
In recent years, the rapid development of the Internet has greatly promote the process of social life and economic and cultural development, human enjoyment of computer networks has brought us convenience and speedy network security issues raised to us more and more to feel grim challenges, cyber crime has become increasingly serious. In this case, the anti-virus software, firewall technology and intrusion detection products, etc. have appeared, and jointly safeguard the safe operation of modern network, how to make the network security defense system in the network security technology continues to evolve, from passive to active has become experts and scholars to study the new content, and intrusion detection technology is the main object of study of this research, therefore, the intrusion detection technology has become an integral part of network security architecture. Is a well-known open source intrusion detection system Snort intrusion detection system can effectively protect information systems security, attention by the field of network security, many experts and scholars engaged in research and development use. With the gradual increase in the network resources and network traffic continue to improve as well as network attack type changing, resulting in the Snort not meet the requirements of network development, thereby missing some of the complex network attacks, causing a serious security risk to the system. Therefore, how to improve the the Snort detection efficiency, enhanced detection performance has become an important content of the research in the field of intrusion detection. In this paper, the analysis of the advantages and disadvantages of Snort system based on use of the advantage of its open source and supports plug for its new intrusions can not be detected high false negative rate and lower rate of detection in Snort system based on the combination of data mining intrusion detection technology, proposes a hybrid intrusion detection system based on Snort system model. Model of the system is the increase in the basic functions of the original Snort system module based on the normal patterns of behavior building blocks, anomaly detection module, a classifier module, rules dynamically generated module expansion module. Mixed intrusion detection system Snort system to increase the dynamic rule generation module, making improvements with dynamic rule extension mechanism is able to detect new intrusion attack behavior, make up Snort typical misuse-based intrusion detection system shortcomings; Snort system increases the normal behavior patterns mining module, the abnormality detection module, so that the mixture of the improved intrusion detection system also has the function of misuse detection and anomaly detection. Thereby improving the efficiency of the detection system. Finally, according to the system design model, a hybrid intrusion detection system based on Snort. Lincoln Laboratory sample data, Profile testing tools for improved system has been tested and verified by the comparison and analysis of the experimental results, the improved hybrid detection system in the detection, detection efficiency has been improved and enhanced. The mixture of the improved intrusion detection system is not only able to dynamically expanding rules, also has the function of the abnormality detection. Thereby greatly enhancing the efficiency of the detection system.
|
Related Dissertations
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- The Design and Implementation of Bicluster Data Analyzing Software,TP311.52
- Research on Clustering Algorithm Based on Mutation Particle Swarm Optimization,TP18
- Research on Fuzzy C-Mean Clustering Algorithm Based on Particle Swarm Optimization and Shuffled Frog Leaping Algorithm,TP18
- Research on Clustering Algorithm Based on Genetic Algorithm and Rough Set Theory,TP18
- Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
- Community-oriented education, personalized learning system and its implementation,TP391.6
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- Data warehouse technology in the banking customer management systems research and implementation,TP315
- Design and Development of Teaching Quality Assessment System Based on Data Mining,TP311.13
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Research on Clustering Algorithm of Data Stream,TP311.13
- Intrusion Detection in Mobile Ad Hoc Networks: A Timed Finite State Machines Approach,TN929.5
- Research of Dynamic Association Rules,TP311.13
- Research on the Security in Wireless Sensor Network,TN915.08
- Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
- Study on the Decision Tree Classification Algorithm and Its Application Based on Rough Set Theory,TP18
- Three-dimensional model based on data mining characterization , indexing and retrieval,TP391.3
- CUSUM algorithm based on improved DNS cache attack detection,TP393.08
- Design and implementation of intrusion detection system based on association rules,TP393.08
- Research on Intrusion Detection Based on Protocol Analysis and Immune Principle,TP393.08
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|