协同分布式入侵检测系统模型  被引量:1

A Co-operation Distributed Intrusion Detection System Model

在线阅读下载全文

作  者:杨小平[1] 窦昱[1] 

机构地区:[1]中国人民大学信息学院,北京100872

出  处:《计算机工程与应用》2002年第15期241-243,246,共4页Computer Engineering and Applications

摘  要:由于入侵行为存在相关性,单纯依靠其中独立的检测器来准确地发现和阻止入侵行为是非常困难的,同样地在整个网络系统里单纯依靠分布式入侵检测系统来准确地分析、发现和阻止入侵行为也是非常困难的,如何实现分布式入侵检测系统中的各个检测器间的协同以及将入侵检测系统与现有的或将有的安全系统协同工作是一件非常迫切和重要的任务。该文提供了一个新的解决方案,它既可以根据需要,随时实现自动高效地配置相互间具有协同能力的入侵检测器,又可以做到和网络上的其他安全系统之间的协同。从而可以极大地减轻网络管理员的安装配置压力,实现自动、高效、一致地保证整个网络系统安全。With the increasing of co-relation of the intrusion activities,it is difficult for a stand-alone sensor to collect data,analyze them and then response against the intrusion activities,and at the same time ,the stand-alone distributed intrusion detection system(IDS)faces the same thing.How to implement the co-operation between the different sensors in the distributed IDS and the co-operation between the various security systems such as firewall,virus defense system,security OS and even security applications is a more important and critical task in current IDS field.This article pro-vides a new solution for building a highly configurable,effective and consistent distributed IDS with the co-operation between the different sensors in the same IDS and the co-operation with other security systems automatically to meet the increasing security needs,and in return such IDS system will greatly lessen the pressure of network administrators and increase security of the whole network.

关 键 词:协同 分布式入侵检测系统 模型 网络安全 防火墙 计算机网络 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象