摘要
首先分析了目前比较热门的入侵防御系统的体系结构,并指出了传统单个入侵防御系统会导致单点故障、拒绝正常服务等一系列问题,同时还存在不能检测分布式协作攻击和未知攻击及性能等问题。为了解决传统IPS上述的缺点,在原有的两类入侵事件的基础上重新划分,把入侵事件分为三类,并结合多传感器数据融合技术和入侵容忍技术提出一种深度入侵防御模型。最后通过仿真实验验证了该模型检测和防御入侵的可行性。
At first, this paper analyses popular IPS in detail and points out it’s advantage and insufficiency, such as single-end failure , denial-of-service and so on. At the same time traditional IPS do not detect distributed cooperation and unknown attack. The intrusion affairs are partitione d three kinds on the basis of two types. Combining data fusion algorithm of multi-sensors an d the intrusion tolerance, a detection and defense-detection and response model based on defense in depth theory is proposed, in order to solve the problem of the traditional IPS. In the end, the simulation results validate the feasibility of this model’s detection and prevention of intrusion.
出处
《计算机应用研究》
CSCD
北大核心
2005年第7期140-142,共3页
Application Research of Computers
基金
国家信息产业部基金资助项目(211070B414)
国家"十五"项目
"211工程"重点学科建设项目(181070H901)
关键词
入侵防御
深度防御
数据融合
Intrusion Prevention
Defense in Depth
Data Fusion