摘要
在分析现有分布式入侵检测系统拓扑结构基础上,设计实现了自组织的层次式大规模网络入侵检测系统。该系统提出入侵检测节点之间自组织的概念,使用组织服务器来将分布式入侵检测系统的检测功能与组织功能分离开来,降低系统实现复杂性,并使系统中不再存在单点失败,当系统中部分检测节点失效后,系统的其余部分仍能够有效的工作。针对网络入侵检测节点,实现了一个完整的协议还原平台。在实际运行中,取得了良好的效果。
Based on the analysis of current distributed intrusion detection system topology, we design a self-organized hierarchical massive network intrusion detection system. We present the idea of self-organization between nodes, and separate detecting function from organizing function with organizer server in the distributed intrusion detection system. It reduces the implement complexity, and avoids the single point of failure. When some nodes of the system are out of work, the others still work well. We realize a complete protocol assembly platform. It does well in practice.
出处
《通信学报》
EI
CSCD
北大核心
2004年第7期86-92,共7页
Journal on Communications
基金
国家"863"计划资助项目(8631040201)
"十五"国防预研基金资助项目(41315.7.3
41316.3.3)
关键词
入侵检测
自组织
层次结构
大规模网络
intrusion detection
self-organized
hierarchy
massive network