earticle

논문검색

A New Two-Stage Search Procedure for Misuse Detection

초록

영어

A new two-stage indexless search procedure is presented that makes use of the constrained edit distance in IDS misuse detection attack database search. The procedure consists of a pre-selection phase, in which the original dataset is reduced and the exhaustive search phase for the database records selected in the first phase. The maximum number of consecutive deletions represents the constraint. Besides eliminating the need for finer exhaustive search in the attack database records in which the detected subsequence is too distorted, the new search procedure also enables better control over the search process in the case of deliberate distortion of the attack strings. Experimental results obtained on the SNORT signature files show that the proposed method offers average search data set reduction in the typical cases of more than 70% compared to the method that uses the unconstrained edit distance.

목차

Abstract
 1. Introduction
 2. Mathematical background
 3. The new signature search algorithm
 4. Experimental work
 5. Conclusion
 References

저자정보

  • Slobodan Petrović NISlab, Department of Computer Science and Media Technology Gjøvik University College, P.O. box 191, 2802 Gjøvik, Norway
  • Katrin Franke NISlab, Department of Computer Science and Media Technology Gjøvik University College, P.O. box 191, 2802 Gjøvik, Norway

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

      0개의 논문이 장바구니에 담겼습니다.