摘要
随着网络入侵行为变得越来越普遍和复杂,传统的单一入侵检测系统已不能满足网络安全的发展需求,针对当前形势,为了提高计算机及网络系统的防御能力,提出了一种基于分布式Agent技术的入侵检测模型,并给出了一种可疑度算法和多IP地址连续报告策略,经测试和论证,系统可有效地阻止已知和未知的攻击行为,最后对系统的整体性能进行了详细描述。
Network-based attacks have become common and sophisticated. For this reason, traditional intrusion detection system based on single layer can't meet the increasingly growing network security's requirement. Under the situation, in order to improve resistive ca- pability of computer and network system , a prototype— — intrusion detection system is presented based on distributed agent, and then a doubt value algorithm and a multi-IP address sequential report policy are proposed. After testing and demonstrating, this system can prevent known and unknown attacks effectively. Finally, the whole capability of this system is particularly introduced.
出处
《计算机工程与设计》
CSCD
北大核心
2005年第5期1241-1244,共4页
Computer Engineering and Design