信息网络安全 ›› 2016, Vol. 16 ›› Issue (5): 23-29.doi: 10.3969/j.issn.1671-1122.2016.05.004

• 技术研究 • 上一篇    下一篇


史国振1, 张萌1(), 付鹏2, 苏铓3   

  1. 1. 北京电子科技学院,北京 100070
    2. 西安电子科技大学计算机学院,陕西西安 710071
    3. 南京理工大学计算机学院,江苏南京210094
  • 收稿日期:2015-12-02 出版日期:2016-05-20 发布日期:2020-05-13
  • 作者简介:


  • 基金资助:

Design and Implementation of IDS Device Detection Tool

Guozhen SHI1, Meng ZHANG1(), Peng FU2, Mang SU3   

  1. 1. Beijing Electronic Science & Technology Institute, Beijing 100070, China
    2. IT Academy, Xidian University, Xi’an Shaanxi 710071, China
    3. IT Academy, Nanjing University of Science and Technology, Nanjing Jiangsu 210094, China
  • Received:2015-12-02 Online:2016-05-20 Published:2020-05-13



关键词: 入侵检测, 检测工具, 规则解析, 重组, 数据包构造


With the rapid development of Internet, network attacks, intrusions and other security problems become increasingly serious. In order to protect the security of networks and computer systems, various network protection tools are emerging, such as firewall, IDS, etc. And IDS has already become an important way to protect the system and network. In order to keep system and network more security, IDS need to be test and evaluate more promptly. Although there are some IDS device testing tools, but there are still some limitations in them. How can it be tested and evaluated convenient and efficient has become the focus of current research. This paper designs a set of IDS device detection tools to analysis types of IDS rules, restructure them, and generate unified alarm file. Through the analysis of alarm files, the rate of false positives and non-response of IDS device can be calculated. It implements structure of different characteristics rules packet. As to different types of alarm information it can analysis and generate alarms unified file. So it has some value of general use.

Key words: intrusion detection, detection tool, rules resolve, restructuring, packet structure
