Dissertation > Excellent graduate degree dissertation topics show

The Application and Research of Intruction Detection System-Snort

Author: WeiZuoYa
Tutor: WuShunXiang;ChenBaoXing
School: Xiamen University
Course: Control Theory and Control Engineering
Keywords: Intrusion detection Detection Performace Application of Snort
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 178
Quote: 1
Read: Download Dissertation

Abstract


Recent years, the internet has got explosive development,which brings the human society, economy, culture infinite opportunity, meanwhile,it also brings information security rigorous challenge. People adopt ani-virus,firewall, intrusion detection technology etc to assure the network security. With the development of network technology, the intrusion detection technology has become the necessary component of network security architecture.Snort intrusion detection system, as a famous open source NIDS,could protect system information security effectively, which gets vast research and application in industry. The Snort detection engine adopts the simple pattern matching strategy. With the increase of net-band and rule-set, the detection load of Snort is becoming heavier;therefore, it is possible that Snort may neglect some severe attacks. So it is crucial to design high efficient pattern matching algorithm for intrusion detection system.The main works of this paper include the following three parts:1、Based on introducing Intrusion Detection System, the paper get through a deep research on Network Intrusion Detection System named Snort. Through analyzing modules of the Snort’S architecture, working flow and rules, the paper points out the performance bottleneck of the Snort2、Based on which the paper gives out the methods to improve snort’s performance: First, the technology of the improved packet capture, which can improve the performance of packet capture by using Memory mapping, NAPI; Second, Third, the technology of optimization rules, which can improve the speed of matching rules by creating efficient rule sets;Third, a dynamic Cache strategy is put forward, in which the recent frequently used rule node pointers ale stored in a Cache block;Fourth, Set threshold to ignore the statistical connection between the packet.3、Unified actually proposed a Snort system model application plan

Related Dissertations

  1. Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
  2. Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
  3. Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
  4. Intrusion Detection in Mobile Ad Hoc Networks: A Timed Finite State Machines Approach,TN929.5
  5. Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
  6. Petri net -based network intrusion detection system Research and Implementation,TP393.08
  7. FSVM -based data mining method and its application to intrusion detection research,TP393.08
  8. IPv4-IPv6 transition technologies CIDF Based Intrusion Detection System,TP393.08
  9. Mechanisms based on trust metrics Research and Implementation of Intrusion Detection System,TP393.08
  10. Research on Intrusion Protective Mechanism of Database Based on User Behavior Mining,TP311.13
  11. The Dynamic Distributed network intrusion patterns,TP393.08
  12. Intrusion Detection in Network Abnormal,TP393.08
  13. Research on Intrusion Detection Based on Semi-Supervised SVM,TP393.08
  14. Lightweight Intrusion Detection System Based on Feature Selection,TP393.08
  15. Research on Detector Generating Algorithm Based on Artificial Immune System,TP393.08
  16. Mobile Ad Hoc Network Intrusion Detection and Response System Based Cluster,TN929.5
  17. Research on Matching Process and Algorithm Improvement of Intrusion Detection,TP393.08
  18. WLAN environment Intrusion Detection Prevention System Design and Implementation,TP393.08
  19. Intrusion detection system alarm integration of key technology research,TP393.08
  20. Attribute Reduction Based on Rough Set and Weighted SVM intrusion detection method,TP393.08
  21. Intrusion detection based on data mining technology research,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile