检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]合肥工业大学计算机与信息学院,安徽合肥230009
出 处:《计算机工程与设计》2005年第5期1241-1244,共4页Computer Engineering and Design
摘 要:随着网络入侵行为变得越来越普遍和复杂,传统的单一入侵检测系统已不能满足网络安全的发展需求,针对当前形势,为了提高计算机及网络系统的防御能力,提出了一种基于分布式Agent技术的入侵检测模型,并给出了一种可疑度算法和多IP地址连续报告策略,经测试和论证,系统可有效地阻止已知和未知的攻击行为,最后对系统的整体性能进行了详细描述。Network-based attacks have become common and sophisticated. For this reason, traditional intrusion detection system based on single layer can't meet the increasingly growing network security's requirement. Under the situation, in order to improve resistive ca- pability of computer and network system , a prototype— — intrusion detection system is presented based on distributed agent, and then a doubt value algorithm and a multi-IP address sequential report policy are proposed. After testing and demonstrating, this system can prevent known and unknown attacks effectively. Finally, the whole capability of this system is particularly introduced.
关 键 词:入侵检测 分布式代理 网络安全 协作 AGENT
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.49