

论文作者:王小玲 李凌 赵可

文章页码:1074 - 1078


Key words:intrusion detection; network-based intrusion detection system; real-time intelligent cooperation engine

摘    要:在分析现有网络入侵检测系统局限性的基础上,提出一个基于模式匹配误用检测技术的分布式网络入侵检测系统模型。该模型可用于应用层协议分析,提高了检测精度;采用协议流分析技术,减少了检测时间与误报率;采用中断会话和防火墙联动,可实现主动响应;在主体智能协作与负载平衡上考虑了其分布式的特性;在Linux环境下构建基于实时智能协作引擎的原型系统,验证该模型的特性。

Abstract: After analyzing limitations of existing network-based intrusion detection system, the paper raised a distributed network-based intrusion detection system mode,l which is based on feature ranking misusing detection technology and can adaptwell to existing network status. Thismodel extends to application layer protocol analysis, so tha,t the precision ofdetection is improved; Protocol flow analyzer is adapted to shorten the detection intervalandmisinformation ratio; Session-haltand fire-wallare introduced to implement active-response. In order to validate features of themode,l RICE-based raw system is built in Linux environmen.t

有色金属在线官网  |   会议  |   在线投稿  |   购买纸书  |   科技图书馆

中南大学出版社 技术支持 版权声明   电话:0731-88830515 88830516   传真:0731-88710482   Email:administrator@cnnmol.com

互联网出版许可证:(署)网出证(京)字第342号   京ICP备17050991号-6      京公网安备11010802042557号