基于分布式的入侵检测研究  被引量:1

Study on Distributed-based Intrusion Detection

在线阅读下载全文

作  者:蔡明[1] 张成军[1] 

机构地区:[1]武汉信息传播职业技术学院,湖北武汉430074

出  处:《软件导刊》2008年第12期161-163,共3页Software Guide

摘  要:传统的入侵检测系统对中小型网络的安全检测发挥了重要的作用,但是随着网络带宽的增加、攻击手段的复杂化,入侵检测系统在可扩展性和检测效率上面临着新的挑战。充分利用分布式技术的特点,提出了一个新型的分布式入侵检测模型,有效地解决了传统的入侵检测模型漏包严重和单点失效问题,并且利用关联分析的方法从日志库中挖掘出新的规则,实现了规则库的自动更新。The traditional intrusion detection system has played a very important role in the small and middle-sized network, but with the increase of the network bandwidth and the complexity of attacking measures, the intrusion detection system face new challenge in extensity and detecting efficacy. By fully utilize the distributed technology, a new distributed intrusion detection system model was created which effectively solve the problems Of serious of package leaking and simple point failing, achieve the automatic upgrade of rule base by searching the new rules in the log base through association analysis. Experimental analysis proved that the new model is practicable in increase of extensity and reduction of false alarm rate and false dismissal rate.

关 键 词:入侵检测 分布式 异常检测 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象