随着IDS技术的不断成熟,近年来面向IDS检测的攻击分类层出不穷.在分析比较三种具有代表性的面向IDS检测攻击分类基础上,针对它们各自在分类数据基础的全面性、攻击特征的具体性、对IDS检测精确度与效率提高的促进性等方面的不足,从攻击的地址信息A、协议状态P和连接状态C等三方面考虑,提出一种基于网络连接的APC攻击分类方法.经过实验分析证明,该攻击分类方法分类数据基础更全面、攻击特征更具体、更易于IDS检测和构造攻击数据.
With the development of intrusion detection system, there have been so many detection-oriented attack classifications recently. In order to overcome the disadvantages which lie in comprehensiveness of classification data foundation, concreteness of attack character and improvement in IDS detection accuracy and efficiency, on account with three attack attributes consist of address information, protocol state and connection state, the paper proposes an attack classification based on connection-APC Class through the analysis and comparison of three detection-oriented attack classifications. After the analysis it is proved that the attack classification in this paper is all-sided, detailed in character, convenient in intrusion detection and conforming attack data.