摘要
分析了当前的入侵检测技术的发展及存在的主要缺陷,介绍了移动Agent的概念及其优点,提出了一种新的基于移动Agent的分布式入侵检测模型MABDIDS。MABDIDS利用移动Agent的优点,设计了针对主机和网络两种环境而分别具有不同运行机制的两种检测主体,通过将多个监控节点组织成层次结构来协同实现分布式入侵检测,解决了当前分布式入侵检测系统中存在的主要问题。
The development of intrusion detection technologies and the existent questions were analysed in this paper. The concept and the advantages of mobile agent were introduced. A new Mobile Agent Based Distributed Intrusion Detection System model MABDIDS was proposed. This model designed two detection entity which have different behavior mechanisms aimed at host and network environment. And it organized the surveillant nodes into hiberarchy. By these measures, MABDIDS performed the distributed intrusion detection and solved the main problems of distributed intrusion detection nowaday.
出处
《网络安全技术与应用》
2005年第6期20-23,共4页
Network Security Technology & Application