摘要
通过模拟黑客攻击,可以对IDS进行性能评估,测试它们的检测率、误报率,从而进一步完善其性能。针对现有IDS测试需大量手工操作的不足,提出一个以APC(地址信息A、协议状态P、连接状态C)攻击分类方法为依据的自适应测试模型。该模型利用事先建立攻击决策库和攻击数据库、各测试环节自动执行,可提高测试速度,使测试过程智能化;通过模拟黑客攻击,有效降低IDS的评估误差。经实验验证,该系统模型是实用有效的。
Simulating hack attack can be used to evaluate detection accuracy and false alarm rate of as Intrusion De tection System(IDS),so that can improve its performance.In order to overcome the disadvantages that IDS evaluation need a great deal of handwork,on account with an attack classification based on connection,APC Class,this paper puts forward an adaptative test model that facilitate simulating attack.The model make attack policy database and attack database in advance and make each part of model automatically execute so that speed up the test procedure and make the procedure intelligently,simulating hack attack can decrease the test error.After the analysis it is proved that the model is useful and effected.
出处
《计算机工程与应用》
CSCD
北大核心
2006年第13期123-126,共4页
Computer Engineering and Applications
基金
国家自然科学基金资助项目(编号:60573050)
北京市优秀人才培养专项经费资助项目(编号:20042D0500103)
关键词
网络安全
性能测试
模型
攻击分类
Z方法
network security,performance test,model,attack classification,Z method