摘要
提出了一个网络环境下分布式入侵检测系统的框架。描述了将原始网络报文分组加工组织成相当于单词和文本的结构形式的方法,通过聚类发现相当于文本类特征词的方法,以及通过分类算法实现网络入侵检测的方法。讨论了控制节点的agent如何将完整的入侵检测任务合理组织分配到分布在各计算节点上的agent,并协调各计算任务的并发过程。
In this essay, a framework for distributed invasion-testing system in network circumstance is achieved by the agents which are distributed in every CPU in network. This essay describes the method that devices profile report into groups and organize them to be the structure, which contains single word and text. Through classified accumulation to find feature words that are equal to profile ones, through classified calculation to realize network invasion -test organizes and distributes the whole invasion-testing task to calculating agent reasonably and coordinate every calculation task.
出处
《计算机工程》
CAS
CSCD
北大核心
2004年第13期104-106,共3页
Computer Engineering
关键词
入侵检测系统
文本聚类
特征词
Invasion-testing system
Classified profile
Feature words