Free and Latest article publishing for websites and ezines!


Research on Implementation and Improvement of Intrusion Detection System Based on Snort

Along with the fast development of the network technology and the universal application of the network environment, the security problem in network is increasingly outstanding. And as a new security means, intrusion detection techniques have displayed its important role. Snort is one powerful lightweight network intrusion detection system. This paper does deeply research on Snort: at first, describes the feature, architecture and working flow of Snort; then, the implementation of Snort intrusion detection system based on Windows platform is achieved. With MySQL database and analyst control console ACID, intrusion events can be managed efficiently.The fast detection engine of the Snort and the detection engine's pattern match algorithms are especially analyzed in this paper. A new multiple pattern match algorithm based on feature value is raised and applied in Snort. According to the experiments results, the new algorithm can improve the efficiency of Snort detection engine. Then applying protocol state analysis in Snort to detect DDOS which to be a multistep attack is put forward, which uses finite state machine to analyses the state transfer process of protocol, then convert the network attack to a process of protocol state transition. The paper especially discusses the detailed state transition process of TCP three times handshake to strength the ability of Snort to detect syn flood attack. Finally, after sum up the former work, some advice to the future work is given.

Recommended Articles from the Networks Category:

Most Viewed Articles in the Networks Category:

  1. Design and Realization of Task Scheduling Algorithm in Grid Environment
  2. Research on Trust Model in P2P Based on Improved Chord Protocol
  3. Design and Implement of VPN with Dynamic Password
  4. The Research of Task Scheduling in Computational Grid Based on DCG3A
  5. Research on Scheduling Disciplines with Self-Similar Traffic Input
  6. Research on Extension of Network Management Functions and System Realization
  7. Research of Incentive Model in P2P Network
  8. Research on Grid Resource Scheduling Model with Three-level and Algorithm
  9. Research on the Replica Selection Strategies in Spatial Information Grid
  10. Research on IP Multicast Access to SUPANET Multicast Management


© 2004-2009 Information-Technology-Articles.com - All Rights Reserved Worldwide.