基于管理代理的分布式入侵检测系统设计

来源期刊:中南大学学报(自然科学版)2007年第6期

论文作者:康松林 樊晓平 费洪晓 胡赐元 孙永新

文章页码:1174 - 1178

关键词:入侵检测系统;网络管理;管理代理;遗传算法

Key words:intrusion detection system; network management; management agent; genetic algorithm

摘    要:将网络管理系统与入侵检测系统相结合,建立基于管理代理的分布式入侵检测系统框架结构。研究管理代理的自治性、协同性以及管理代理间消息通信机制,建立管理代理的功能结构,设计基于遗传算法的调度Agent算法。从网络的各个层次分析管理信息库中与入侵检测有关的管理对象,建立检测规则库。完成分布式多层次结构化的具有自安全性的入侵检测系统的开发,达到管理代理对网络和主机监听目的。研究结果表明:根据攻击的本质特征,使用从管理信息库的统计数据中获取检测规则的方法,能有效实现对隐蔽和复杂攻击的检测。

Abstract: Combined network management system with intrusion detection system(IDS), the architecture of distributed intrusion detection system based on management agent was established. Good properties such as autonomy, cooperativity, communication mechanism among management agent were studied. Function structure of management agent was established and scheduling agent algorithm was also designed based on genetic algorithm. Management objects related to intrusion detection in management information base(MIB) were analyzed to form rules from different network levels. A distributed intrusion detection system with hierarchical structure and self-security was designed to monitor the running context of the system, and the rules were mined in intrusion detection from MIB according to the essence of network attack. The result shows that this method is efficient enough to meet the need of active detect complex intrusion.

基金信息:国家自然科学基金资助项目
湖南省自然科学基金资助项目

相关论文

  • 暂无!

相关知识点

  • 暂无!

有色金属在线官网  |   会议  |   在线投稿  |   购买纸书  |   科技图书馆

中南大学出版社 技术支持 版权声明   电话:0731-88830515 88830516   传真:0731-88710482   Email:administrator@cnnmol.com

互联网出版许可证:(署)网出证(京)字第342号   京ICP备17050991号-6      京公网安备11010802042557号