摘要
通过分析当前入侵响应系统存在的问题,提出了一种基于Petri网的工作流和J2EE框架构建的入侵响应模型,该模型先对所有报警事件进行过滤然后予以响应,并在响应当前报警事件的同时根据报警信息之间的关系,对进一步可能发生的攻击作出在线的预警并产生相应的响应措施。通过实验分析,该模型能够在入侵发生后主动采取措施阻击入侵的延续和降低系统的损失,保护受害系统。
Through analyzing the existence questions of current intrusion response system, this paper proposes an intrusion response model based on Petrl Net workflows and J2EE framework. This model filtrates alarm before response, at the same time, it can also predict the coming attacks via on-line mode and make the corresponding response measures according to the relations among alarm message. Through experiment analysis, the intrusion response systems can forwardly take measures to hold back continuing intrusion, minimize the loss of the system and protect the suffering systems after the intrusion happened.
出处
《电脑开发与应用》
2007年第1期49-52,共4页
Computer Development & Applications
关键词
肯定选择算法
PETRI网
工作流
入侵响应
positive selection algorithm, Petri net, workflows ,intrusion response