摘要
通过对现有入侵检测系统的研究,提出了一种基于多代理技术的入侵检测系统模型,并且对该模型的结构、组成和代理的处理流程进行了描述。该模型是一个开放的系统模型,具有很好的可扩展性,易于加入新的入侵检测代理,也易于增加新的入侵检测模式。代理之间的协同采用代理守护进程来实现。
By dealing with the current intrusion detection system (IDS), a system model with multi- agent technique is presented, and its architecture, components and intrusion detection agent (IDA) processing flow chart are described in this paper, as well. This model is extended, as an open system, to which the new IDAs and ID modes can be easily added. Communications of these agents are realized by DEMON threads.
出处
《空军雷达学院学报》
2001年第4期45-48,55,共5页
Journal of Air Force Radar Academy