期刊文献+

基于分布式网络入侵检测系统的研究及其实现

Study & realization of the distributed network based intrusion detection system
下载PDF
导出
摘要 在分析现有网络入侵检测系统局限性的基础上,提出一个基于模式匹配误用检测技术的分布式网络入侵检测系统模型。该模型可用于应用层协议分析,提高了检测精度;采用协议流分析技术,减少了检测时间与误报率;采用中断会话和防火墙联动,可实现主动响应;在主体智能协作与负载平衡上考虑了其分布式的特性;在Linux环境下构建基于实时智能协作引擎的原型系统,验证该模型的特性。 After analyzing limitations of existing network-based intrusion detection system, the paper raised a distributed network-based intrusion detection system model, which is based on feature ranking misusing detection technology and can adapt well to existing network status. This model extends to application layer protocol analysis, so that, the precision of detection is improved; Protocol flow analyzer is adapted to shorten the detection interval and misinformation ratiot Session-halt and fire-wall are introduced to implement active-response. In order to validate features of the model, RICE-based raw system is built in Linux environment.
出处 《中南大学学报(自然科学版)》 EI CAS CSCD 北大核心 2005年第6期1074-1078,共5页 Journal of Central South University:Science and Technology
关键词 入侵检测 网络入侵检测系统 实时智能协作引擎 intrusion detection, network-based intrusion detection system real-time intelligent cooperation engine
  • 相关文献

参考文献11

  • 1Ptacek T H.Insertion,evasion and denial of service:eluding network intrusion detection[R].Alberta:Secure Netuaorks Inc,1998.
  • 2韩东海 王超.入侵检测系统示例剖析[M].北京:清华大学出版社,2002.31-36.
  • 3Snort.Snort Users Manual[EB/OL].http://www.snort.org,2004-03.
  • 4Stevens W R.TCP/IP Illustrated.Volume1:The Protocols[M].Beijing:China Machine Press,2000.24-38.
  • 5SourceFire inc.Protocol Flow Analyzer[EB/OL].http://www.sourcefire.com,2003.
  • 6IETF.IDWG[EB/OL].http://www.ietf.org,2004-03.
  • 7SourceFire Inc.Intelligent Threat Mitigation & Response[EB/OL].http://www.sourcefire.com,2003-02.
  • 8SourceFire Inc.Protocol Flow Analyzer[EB/OL].http://www.sourcefire.com,2003-02.
  • 9Laing B.How to guide-implementing a network based intrusion detection system[EB/OL].http://www.iss.com,2002-12.
  • 10Ilgun K.USTAT:A real-time intrusion detection system for UNIX[D]:Santa Barbara:University of California Santa Barbara,1992.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部