arXiv:2601.11998cs.CRcs.AI2026-01被引 2

融合规则与异常检测,提升对新型网络攻击的识别能力。

Hybrid IDS Using Signature-Based and Anomaly-Based Detection

  • 结合规则匹配与行为异常分析,实现双重防护。
  • 可有效降低误报率,增强对未知攻击的发现能力。
  • 适合金融、航空等高安全需求场景使用。

入侵检测系统(IDS)对于保护计算机系统和网络免受持续演进的网络威胁至关重要。传统IDS主要分为基于签名和基于异常两种类型,各有优劣,如难以发现未知攻击且易产生高误报率。本文综述了混合型入侵检测系统(Hybrid IDS),该系统融合了基于签名与基于异常的检测技术,以提升攻击检测能力。文章梳理了近期相关研究,将现有模型按功能分类,并讨论其优势、局限性及应用场景,涵盖金融系统、空中交通管制和社交网络等。同时,还分析了当前研究趋势,如基于机器学习的方法和云部署方案。最后,提出了未来研究方向,旨在开发成本更低、检测新兴复杂攻击能力更强的混合型系统。

原文摘要 · Abstract (English)

Intrusion detection systems (IDS) are essential for protecting computer systems and networks against a wide range of cyber threats that continue to evolve over time. IDS are commonly categorized into two main types, each with its own strengths and limitations, such as difficulty in detecting previously unseen attacks and the tendency to generate high false positive rates. This paper presents a comprehensive survey and a conceptual overview of Hybrid IDS, which integrate signature-based and anomaly-based detection techniques to enhance attack detection capabilities. The survey examines recent research on Hybrid IDS, classifies existing models into functional categories, and discusses their advantages, limitations, and application domains, including financial systems, air traffic control, and social networks. In addition, recent trends in Hybrid IDS research, such as machine learning-based approaches and cloud-based deployments, are reviewed. Finally, this work outlines potential future research directions aimed at developing more cost-effective Hybrid IDS solutions with improved ability to detect emerging and sophisticated cyberattacks.

入侵检测混合检测网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。