摘要
针对现有的入侵检测系统具有成本高、检测能力低等问题,设计实现了基于嵌入式的入侵检测系统。该系统以ARM9微处理器为核心,并使用Linux-2.4内核作为底层操作系统。该设计结合了误用检测技术与协议分析技术完成对数据报文的实时检测,并采用无监督聚类算法提取入侵特征,扩充了现有的入侵规则库。实验结果表明,在一定条件下该系统具有较高的稳定性及较好的检测能力。
As for existing intrusion detection system that is namely high costs and low ability on detection.A embedded intrusion detection system is designed and implemented.The systemused ARM9 microprocessor and the Linux-2.4 kernel as the operating system. It combined misuse detection and protocol analysis technology to detect the data packet in the network,and used unsupervised clustering algorithm to extract the intrusion feature,the existing intrusion rule is expanded.Experimental result showed that this system has high stability and better detection ability under certain conditions.
出处
《计算机工程与设计》
CSCD
北大核心
2011年第1期21-23,27,共4页
Computer Engineering and Design
基金
国家自然科学基金项目(50372037)
陕西省科技厅自然科学基础研究计划基金项目(SJ08E103)
陕西科技大学科研启动基金项目(BJ10-01)
关键词
嵌入式技术
入侵检测系统
防火墙
无监督聚类
网络安全
embedded technology
intrusion detection system
firewall
unsupervised clustering
network security