Dissertation > Excellent graduate degree dissertation topics show
Research of Snort-based Intrusion Detection System
Author: DaiWenChao
Tutor: ShenFuKe
School: East China Normal University
Course: Applied Computer Technology
Keywords: Intrusion Detection Multi-pattern matching Distributed
CLC: TP393.08
Type: Master's thesis
Year: 2006
Downloads: 371
Quote: 10
Read: Download Dissertation
Abstract
|
In recent years, the intrusion detection technology has not only become the hotspot of network security research, and has broad market prospects. Information security technology gradually breaking down the conventional passive methods of detection and filtering, is moving in the direction of active defense, firewall-based security architecture model has been difficult to meet the needs of network security, in this situation, intrusion detection more attention has been paid. Intrusion detection has been generally considered to the network firewall supplement, extend the security management ability of the system administrator. However, with the rapid development of the Internet, network bandwidth than before increasing the speed of the network faster and faster, the need to improve the detection efficiency of intrusion detection systems, and improve the efficiency of the system is simply to intrusion detection The core of the system - detection engine optimization improvements. Snort is a lightweight network intrusion detection system, it has the ability of real-time analysis of data traffic and IP packet log, and can perform protocol analysis, content searching or matching. It can detect a variety of attacks, and attacks carried out real-time alerts. In addition, Snort has good scalability and portability. On the basis of analyzing the the Snort system architecture, workflow and rules structure detection engine of the system and its pattern matching algorithm used in the focus of research and discussion, for the deficiencies of the original system mode matching algorithm, using the a hash-based method of multi-mode matching the the algorithm-LRK algorithm, and LRK algorithm to optimize the algorithm, and applied to the Snort detection engine module. The experiments prove that the the LRK algorithm is improved match than the original system detects engine speed has been greatly improved. Subsequently, the centralized architecture for Snort system, Snort applications in a distributed network environment. Hierarchical distributed architecture to achieve by setting multiple Snort detection node, in the above method to develop visual management interface, unified distributed detection and centralized management, enhanced ease of use of Snort, but also greatly reduce the burden on the Snort detection engine, improving Snort's ability to adapt to a high-bandwidth network. Finally, we summarized the work, and further optimization suggestions for improvement.
|
Related Dissertations
- Study on Channel Allocation of Multi-Channel MAC Protocol in Ad-Hoc Network,TN929.5
- Research of Fault Injection for a Distributed System,TP338.8
- The Research of Fault-Tolerant Techniques for Parallel/Distributed Network Simulator PDNS,TP302.8
- Research and Implementation of Retrieval System on Massive Mail,TP393.098
- Research and Design of One Kind of Paper’s QCS That Based on Embedded System,TP368.1
- Micro- grid with distributed power control strategy research,TM61
- Research of Communication Mechanism in the Distributed Network Based on Mobile Agent,TP393.02
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
- M Petrochemical Company CCR unit implementation and management of,F426.72
- Based on Modbus Protocol pressure medical gas distribution monitoring system development,R197.39
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- Research and Application of Map/Reduce Based Distributed Log Analyzer,TP311.52
- The Design and Implementation of Distributed Database Based on Oracle of Mobile CRBT,TP311.13
- Equipment management information system based on distributed three-tier application development and research,TP311.52
- Compressed Sensing Based Abnormal Events Detection in Wireless Communication Net-works,TN929.5
- Research and Implementation of Key Techniques of Building Distributed System,TP338.8
- Design and Implementation of Distributed Video Storage System,TP333
- Design and Implementation of the Traffic Cleaning Management System Based on the Alarm,TP311.52
- Textile workshop Distributed Production Management and Monitoring System,TP311.52
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|