高级检索
    刘利军 怀进鹏. 基于有穷自动机的网络扫描检测算法研究与实现[J]. 计算机研究与发展, 2006, 43(3): 417-422.
    引用本文: 刘利军 怀进鹏. 基于有穷自动机的网络扫描检测算法研究与实现[J]. 计算机研究与发展, 2006, 43(3): 417-422.
    Liu Lijun and Huai Jinpeng. Research of a Network Scan Detection Algorithm Based on the FSA Model[J]. Journal of Computer Research and Development, 2006, 43(3): 417-422.
    Citation: Liu Lijun and Huai Jinpeng. Research of a Network Scan Detection Algorithm Based on the FSA Model[J]. Journal of Computer Research and Development, 2006, 43(3): 417-422.

    基于有穷自动机的网络扫描检测算法研究与实现

    Research of a Network Scan Detection Algorithm Based on the FSA Model

    • 摘要: 网络扫描通常是入侵的前奏,准确的检测网络扫描可以对网络入侵起到重要的预警作用.现有的网络扫描检测机制都过于简单且易于被攻击者逃避.提出了一种基于有穷自动机模型检测网络扫描的入侵预警算法(FSA-based intrusion pre-alert algorithm, SBIPA),用自动机状态迁移图表达扫描报文序列,同时设计了3种不同的机制基于自动机模型对扫描事件进行检测,并讨论了算法实现中的关键技术.实验表明,该算法能在更准确的检测普通扫描的同时,对分布式、多类型混杂扫描等现有技术难以检测的隐蔽扫描也有很好的检测效果,有效弥补了现有同类技术的不足.

       

      Abstract: Network scan is often the prelude of the network intrusion. Thus precise detection of the network scan plays an important role in the pre-alert of the network intrusion. But the current scan detection technologies are too simple and may be evaded by attackers easily. In this paper, based on the analysis of both the scan and detection technologies, a detection algorithm called SBIPA(FSA-based intrusion pre-alert algorithm) is proposed based on the FSA(finite state automata) model and the key implementation technology is analyzed. The state transfer diagram is used to illustrate the network scan packet series, and three different mechanisms are designed to detect the scan event based on FSA. Experiment reveals that this algorithm not only can detect the single type scan activity more precisely, but also can detect the unobvious scan such as distributed and multi-type mixed scan very well, which can't be detected by other detection technologies. It is believed that it eliminates the limitations of the current scan detection technology and has an important research and practice value.

       

    /

    返回文章
    返回