Environment Dependent Performance Tuning forNetwork Intrusion Detection System

碩士 === 中原大學 === 資訊工程研究所 === 93 === With the Internet seeing more and more attacks, and attacking skills evolving. Internet attack model has changed from sending intrusion packets to specific target system to arbitrarily sending packets to intrude any vulnerable computers on Internet. In case that ou...

Full description

Bibliographic Details
Main Authors: Cheng-Hsiu Liu, 劉政秀
Other Authors: Hsiao-Rong Tyan
Format: Others
Language:zh-TW
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/18745525969712986542
id ndltd-TW-093CYCU5392029
record_format oai_dc
spelling ndltd-TW-093CYCU53920292015-10-13T15:06:51Z http://ndltd.ncl.edu.tw/handle/18745525969712986542 Environment Dependent Performance Tuning forNetwork Intrusion Detection System 以環境相依之防禦網為基礎提升網路入侵偵測系統之效能 Cheng-Hsiu Liu 劉政秀 碩士 中原大學 資訊工程研究所 93 With the Internet seeing more and more attacks, and attacking skills evolving. Internet attack model has changed from sending intrusion packets to specific target system to arbitrarily sending packets to intrude any vulnerable computers on Internet. In case that our network environment does not provide the service or does not have the software vulnerability certain intrusion packet targeted. But the detection rule database of the intrusion detection system deployed in our network environment has these signatures, these attacking packets can easily cause a large amount of alerts to be generated and degrade the performance of the IDS. Therefore, we proposed a method to apply the knowledge about the network environment in tuning intrusion detection system, By customizing the detection rule base, the size of the detection rule database can be reduced, which leads to decreased amount of signature comparison and less unnecessary alerts. In this way, the intrusion detection system can save computing resources and concentrate on the more vulnerable parts of the system and improve its performance. Hsiao-Rong Tyan 田筱榮 2005 學位論文 ; thesis 59 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 中原大學 === 資訊工程研究所 === 93 === With the Internet seeing more and more attacks, and attacking skills evolving. Internet attack model has changed from sending intrusion packets to specific target system to arbitrarily sending packets to intrude any vulnerable computers on Internet. In case that our network environment does not provide the service or does not have the software vulnerability certain intrusion packet targeted. But the detection rule database of the intrusion detection system deployed in our network environment has these signatures, these attacking packets can easily cause a large amount of alerts to be generated and degrade the performance of the IDS. Therefore, we proposed a method to apply the knowledge about the network environment in tuning intrusion detection system, By customizing the detection rule base, the size of the detection rule database can be reduced, which leads to decreased amount of signature comparison and less unnecessary alerts. In this way, the intrusion detection system can save computing resources and concentrate on the more vulnerable parts of the system and improve its performance.
author2 Hsiao-Rong Tyan
author_facet Hsiao-Rong Tyan
Cheng-Hsiu Liu
劉政秀
author Cheng-Hsiu Liu
劉政秀
spellingShingle Cheng-Hsiu Liu
劉政秀
Environment Dependent Performance Tuning forNetwork Intrusion Detection System
author_sort Cheng-Hsiu Liu
title Environment Dependent Performance Tuning forNetwork Intrusion Detection System
title_short Environment Dependent Performance Tuning forNetwork Intrusion Detection System
title_full Environment Dependent Performance Tuning forNetwork Intrusion Detection System
title_fullStr Environment Dependent Performance Tuning forNetwork Intrusion Detection System
title_full_unstemmed Environment Dependent Performance Tuning forNetwork Intrusion Detection System
title_sort environment dependent performance tuning fornetwork intrusion detection system
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/18745525969712986542
work_keys_str_mv AT chenghsiuliu environmentdependentperformancetuningfornetworkintrusiondetectionsystem
AT liúzhèngxiù environmentdependentperformancetuningfornetworkintrusiondetectionsystem
AT chenghsiuliu yǐhuánjìngxiāngyīzhīfángyùwǎngwèijīchǔtíshēngwǎnglùrùqīnzhēncèxìtǒngzhīxiàonéng
AT liúzhèngxiù yǐhuánjìngxiāngyīzhīfángyùwǎngwèijīchǔtíshēngwǎnglùrùqīnzhēncèxìtǒngzhīxiàonéng
_version_ 1717761817319571456