DOUBLE-LAYER INTRUSION DETECTION METHOD BASED ON NDIS-HOOK AND SPI
Traditional intrusion detection systems, either in application layer or in kernel layer, have faults in capture and analysis for network data packets. After analyzing and comparing the capture mechanisms of windows operating system for network data packet, we design a double-layer intrusion detection model based on the NIDS-HOOK and SPI, and implement its key techniques. The experimental results show that the performance of the double-layer intrusion detection model is superior to the traditional intrusion detection model.
SPI (Service Provider Interface) Network Driver Interface Specification (NDIS) Intrusion Detection System (IDS)
F.M. Dong J.F. Liu R. Zhang
Institute of Intelligent Vision and Image Information Affiliation, China Three Gorges University, Yichang 443002, China
国际会议
北京
英文
1-5
2008-09-26(万方平台首次上网日期,不代表论文的发表时间)