摘要
介绍了入侵检测及入侵响应系统中的自适应技术。提出了基于代理的自适应分层入侵检测系统(AAHIDS,Agent-based Adaptive Hierarchical Intrusion Detection System)和基于代理的自适应入侵响应系统(AIRS,Agent-based AdaptiveIntrusion Response System)。它们通过调整负责检测入侵行为的系统资源来实现自适应性,动态调用新的底层检测代理的组合以及调整与这些底层代理相关的置信度来适应变化的环境。通过增加过去已获得成功的响应机制的权值,使成功的响应机制获得更多的调用机会来实现响应的自适应性。
It introduces adaptation in intrusion detection and intrusion response. An agent- based adaptive hierarchical intrusion detection system (AAHIDS) and agent- based adaptive intrusion response system (AAIRS) are brought forth. They adjust the system resource used to detect intrusion action to realize adaptation, adapt to the variant circumstance by invoking new combination of low level detection agent dynamic and adjusting the confidence metric of these low level agent. Finally they increase the weight of the successful response, which make the response get more chance to be called to realize the adaptation of the response system.
出处
《计算机技术与发展》
2006年第2期229-231,234,共4页
Computer Technology and Development
基金
国家自然科学基金(60173037
70271050)
江苏省自然科学基金(BK2005146)
江苏省自然科学基金预研项目(BK2004218)
江苏省高技术研究计划(BG2004004
BG2005037)
国家"八六三"高科技项目(2005AA775050)
江苏省计算机信息处理技术重点实验室基金(kjs050001)
关键词
入侵检测
入侵响应
移动代理
自适应
intrusion detection
intrusion response
mobile agent
adaptive