Dissertation > Excellent graduate degree dissertation topics show

Research on Network Intrusion Prevention System Based on Snort

Author: LiHui
Tutor: LiuZuoHua
School: Changchun University of
Course: Computer Software and Theory
Keywords: Intrusion prevention system Support Vector Machine Snort intrusion detection system Classification of learning system firewall
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 32
Quote: 0
Read: Download Dissertation

Abstract


With the increasing number of computer networks and development of network attack technology, the new attack after another, the traditional security technologies have their own shortcoming, and could not to ensure good network security. Firewall technology is a passive, static detection technology, it can not detect the attacks within the network, and intrusion detection technology can only detect known attacks, but can do nothing to the unknown attacks. IPS (Intrusion Prevention System, PS) is a network security technology, which remedy the shortages of firewall technology and intrusion detection system from network security technology.Intrusion prevention system is a positive, proactive security defense tool, when the intrusion prevention system detects the attacks, attack packets can be automatically discarded or block attack sources, which can protect the host or network real-time from damaging. But the existing detection algorithm which use built-in intrusion prevention system is not perfect, make the system a high rate of false positive and false negative rate, so this article is designed to use the support vector machines (Support Vector Machines, SVM) applied to the Snort After the Linux firewall, intrusion detection and intrusion prevention capabilities to achieve the linkage, to solute the existing lack of intrusion defense system.This article design the Network Intrusion Prevention System which using Intrusion Detection System Snort_inline and Netfilter configured iptables firewall interaction. When Snort_inline and firewall communication, Snort_inline work in user space, iptables configured Netfilter firewall configuration interaction work in kernel space, we need to spread data packets from kernel space to user space for intrusion detection. If all packets of the kernel space are copied to user space, processing speed will be reduced, at the same time will also affect system performance. This can be improved:As iptables configured Netfilter packet filtering firewall has the function of the packet filtering,the legitimate traffic which the firewall can be determined directly can directly through the intrusion detection module, the illegal traffic would directly discarded. Firewall may pass packets which need to detect to the intrusion detection module, which can increase data processing speed. Because of the high rate of Snort false positives and false negative view of the relatively defects, misuse detection techniques for the current problems, improved the Snort intrusion detection module, improved by adding the classification of support vector machine learning function, training learning through the data, reduced System false alarm rate and improve the detection accuracy of the system, made the system has good generalization ability.This article is designed Snort network intrusion prevention system based on modular design, the system has good interactivity and scalability.

Related Dissertations

  1. Research on Automatic Detection Algorithm for Substructure Distress of Highway Pavement Based on SVM,U418.6
  2. Research on Autamatic Music Structrue Analysis,TN912.3
  3. Research on Transductive Support Vector Machine and Its Application in Image Retrieval,TP391.41
  4. Fault Diagnosis Method Based on Support Vector Machine,TP18
  5. Process Support Vector Machine and Its Application to Satellite Thermal Equilibrium Temperature Prediction,TP183
  6. Research for Infrared Image Target Identification and Tracking Technology,TP391.41
  7. Study on the Road Condition Monitoring Based on Vehicular 3D Acceleration Sensor,TP274
  8. Research of Diagnosing Cucumber Diseases Based on Hyperspectral Imaging,S436.421
  9. The Research on Intrusion Detection System Based on Machine Learning,TP393.08
  10. Research on Improved K Neighbor Support Vector Machine Algorithm Faced Text Classification,TP391.1
  11. Research on Face Recognition Based on AdaBoost Algorithm,TP391.41
  12. Research on Feature Extraction, Selection and Classification Algorithms for Pulmonary CAD,TP391.41
  13. Research on Subimage Selection and Mathching Method for Synthetic Aperture Radar(SAR) Target Recognition,TN957.52
  14. Research of Facial Expression Recognition Algorithm,TP391.41
  15. Fundus Image Segmentation Based on SVM and Template Matching,TP391.41
  16. Research and Realization of License Plate Character Recognition Algorithm Based on SVM,TP391.41
  17. Cloud Classification Based on Geostationary Meteorological Satellite Imagery,TP391.41
  18. Design and Implementation of Assistant Management System Server Based on Hardware Firewall,TP393.08
  19. Firewall and three switch - based campus network security policy research,TP393.08
  20. The Studies on Some Improvements of the GA and Their Applications in SVM,TP18
  21. Gansu Fuyuan Chemical analysis and design of integrated office platform,TP311.52

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile