摘要
介绍了公共入侵检测框架 (CIDF)理论 ,分析了 agent及其 multi- agent的特性 ,并指出了当前 IDS存在的问题 .在上述讨论的基础上 ,提出了一个基于 multi- agent的入侵检测模型 .该模型采用层次结构组织各种 Agent,具有良好的分布性、智能性和可维护性 ,不仅能够有效地解决系统扩展问题和单点失效问题 。
This paper introduces the theory of CIDF, analyzes the characteristics of agent and multi agent, and points out the flaw of existing IDS. On the basis of the above discussion, a multi agent based intrusion detection model is proposed. This model adopts hierarchical structure to organize and manage all kinds of agents.It is distributed, intelligent and maintainable, and not only resoles the problems of scalability and a single point of failure effectively, but also enhancing the whole systems detection efficiency greatly.
出处
《小型微型计算机系统》
CSCD
北大核心
2003年第6期995-998,共4页
Journal of Chinese Computer Systems
基金
国家关键基础研究项目 ( G19990 3 2 70 0 )资助