入侵检测是网络安全中极其重要的一环,异常检测是近年来入侵检测研究领域的热点。从分析入侵检测和网络安全模型间的关系开始,介绍入侵检测的概念和入侵检测系统的抽象模型,重点讨论基于网络数据、基于系统调用和基于系统调用参数的异常检测技术方法,对3种技术的重要研究方法进行了分析。指出入侵检测目前应尽量降低入侵检测系统对目标系统的性能影响和重点解决入侵异常检测系统的性能开销问题。随着网络环境的不断变化和入侵攻击手段的不断推陈出新,入侵异常检测未来的研究趋势之一是在入侵异常检测系统中增加可视化情景再现过程。
Intrusion detection is an extremely important aspect of network security. The Anomaly intrusion detection research is one of highlighted topics of intrusion detection. The relationship between intrusion detection and network security model is reviewed. The concept of intrusion detection and the abstract model of intrusion detection system are introduced. Three developing technologies including network data based anomaly detection, system call based anomaly detection, and system call arguments based anomaly detection are discussed in detail. Most important research methods of those three technologies are summarized. Finally, the future development of this research domain is presented.