Hybrid Network Intrusion Detection System

孙云,黄皓
DOI: https://doi.org/10.3969/j.issn.1000-3428.2008.09.059
2008-01-01
Abstract:Intrusion Detection System(IDS) has been harassed by false positive and false negative problem.Common IDS using single detection mode is hard to solve this problem effectively.This paper analyzes the characteristics of network flow and presents a new method,called hybrid IDS,combining misuse detection mode and anomaly detection mode,the method can overcome the shortcomings of IDS using single mode.Experiments show that the new method can improve IDS detection rate and decrease false alerts effectively.
What problem does this paper attempt to address?