摘要
由于漏洞扫描器和入侵检测系统都有不同程度的产生误报和漏报的缺陷,提出了将这两个系统进行联动的模型和实现方案。该模型通过开放接口的方式实现联动,将漏洞信息和报警信息传递到联动机制中的预处理器,根据策略库的关联规则进行联动分析,可以很大程度上降低误报和漏报的比例,提高检测的效率。
Both vulnerability scanner and intrusion detection system (IDS) suffer from the drawback of producing false positive and false negative results. So a correlation model between the vulnerability scanner and IDS is proposed in this paper. The model uses the open interface to implement correlation. First, the vulnerability information and alerts alarms are transmitted into the preprocessor; second, execute the correlation analysis according to the rules in policy database. This method can greatly reduce the false positive and false negative rates, enhancing the detection efficiency.
出处
《计算机安全》
2009年第3期35-37,45,共4页
Network & Computer Security
关键词
漏洞扫描
入侵检测
联动
vulnerability scan
intrusion detection
correlation