Mining Regular Expression Rules based on q-grams
- 한국스마트미디어학회
- 스마트미디어저널
- Vol8, No.3
-
2019.0917 - 22 (6 pages)
-
DOI : 10.30693/SMJ.2019.8.3.17
- 8
Signature-based intrusion systems use intrusion detection rules for detecting intrusion. However, writing intrusion detection rules is difficult and requires considerable knowledge of various fields. Attackers may modify previous attempts to escape intrusion detection rules. In this paper, we deal with the problem of detecting modified attacks based on previous intrusion detection rules. We show a simple method of reporting approximate occurrences of at least one of the network intrusion detection rules, based on q-grams and the longest increasing subsequences. Experimental results showed that our approach could detect modified attacks, modeled with edit operations.
Ⅰ. INTRODUCTION
Ⅱ. RELATED WORK
Ⅲ. PROPOSED METHOD
Ⅳ. EXPERIMENTAL RESULTS
Ⅴ. CONCLUSION
(0)
(0)