数据包采样方法是提升数据包处理能力很好的方法,在网络流量监测分析中得到了广泛应用。然而,传统的数据包采样算法应用在IDS中会极大降低入侵检测率。针对入侵检测的特性,利用攻击流量和正常流量在时间上的连续性,提出了一种新的数据包采样方法,在保证检测率的前提下,极大地提升了IDS的处理能力。
Packet sampling which was widely used in network monitoring is a good method to upgrade data packet processing capacity. But the traditional packet sampling algorithm will result in substantial intrusion detection rate reduction. This paper raised a new packet sampling algorithm which used the normal and attacks flow of traffic in the continuity of time against intrusion detection. It could improve IDS' s packet processing capacity in the premise, there was still very good detection rate.