信息网络安全 ›› 2016, Vol. 16 ›› Issue (5): 23-29.doi: 10.3969/j.issn.1671-1122.2016.05.004

• 技术研究 • 上一篇    下一篇

IDS设备检测工具的设计与实现

史国振1, 张萌1(), 付鹏2, 苏铓3   

  1. 1. 北京电子科技学院,北京 100070
    2. 西安电子科技大学计算机学院,陕西西安 710071
    3. 南京理工大学计算机学院,江苏南京210094
  • 收稿日期:2015-12-02 出版日期:2016-05-20 发布日期:2020-05-13
  • 作者简介:

    史国振(1974—),男,河南,副教授,博士,主要研究方向为信息安全、嵌入式系统;张萌(1988—),男,河南,硕士研究生,主要研究方向为信息安全;付鹏(1990—),男,江西,硕士研究生,主要研究方向为信息安全;苏铓(1987—),女,内蒙古,讲师,博士,主要研究方向为信息安全。

  • 基金资助:
    国家高技术研究发展计划(国家863计划)[2012AA013102]

Design and Implementation of IDS Device Detection Tool

Guozhen SHI1, Meng ZHANG1(), Peng FU2, Mang SU3   

  1. 1. Beijing Electronic Science & Technology Institute, Beijing 100070, China
    2. IT Academy, Xidian University, Xi’an Shaanxi 710071, China
    3. IT Academy, Nanjing University of Science and Technology, Nanjing Jiangsu 210094, China
  • Received:2015-12-02 Online:2016-05-20 Published:2020-05-13

摘要:

随着互联网的高速发展,网络攻击和入侵等安全问题日益严重。为了保护网络和计算机系统的安全,各种网络防护工具不断涌现,IDS已成为保护系统和网络安全的重要手段之一。为了更好地维护系统和网络安全,用户对IDS进行测试和评估的要求也越来越迫切。现有的对IDS设备进行测试的工具都具有一定的局限性,因此如何高效、方便、快捷地对IDS进行测试和评估成为当前的研究重点。文章设计了一套IDS设备检测工具,能够对不同类型的IDS规则进行分析、重组,并生成统一的报警文件,通过对报警文件的分析,可对IDS设备的漏报率、误报率等进行检测。文章设计的系统能够实现不同特征规则的检测数据包构造,对不同类型IDS设备的报警信息进行解析,生成统一的报警文件,具有良好的通用性和使用价值。

关键词: 入侵检测, 检测工具, 规则解析, 重组, 数据包构造

Abstract:

With the rapid development of Internet, network attacks, intrusions and other security problems become increasingly serious. In order to protect the security of networks and computer systems, various network protection tools are emerging, such as firewall, IDS, etc. And IDS has already become an important way to protect the system and network. In order to keep system and network more security, IDS need to be test and evaluate more promptly. Although there are some IDS device testing tools, but there are still some limitations in them. How can it be tested and evaluated convenient and efficient has become the focus of current research. This paper designs a set of IDS device detection tools to analysis types of IDS rules, restructure them, and generate unified alarm file. Through the analysis of alarm files, the rate of false positives and non-response of IDS device can be calculated. It implements structure of different characteristics rules packet. As to different types of alarm information it can analysis and generate alarms unified file. So it has some value of general use.

Key words: intrusion detection, detection tool, rules resolve, restructuring, packet structure

中图分类号: