摘要
骨干网的大流量要求实现骨干网入侵检测系统必须改变传统的入侵检测系统结构模型并采用高效的入侵检测技术.在对骨干网入侵检测系统的关键技术进行深入研究的基础上,设计并实现了一种适用干骨干网的基于规则的入侵检测系统BNIDS(Backbone Network Intrusion Detection System).讨论了BNIDS系统的并行集群检测模型、报文捕获机制和基于规则的分析引擎.试验结果表明,可扩展的BNIDS系统能够对骨干网流量进行实时入侵检测分析.
In order to change the traditional intrusion detection system architecture modei by adopting some ef ficient intrusion detection techniques in an intrusion detection system (IDS) for backbone network, based on in-depth research on the key techniques of the IDS for backbone network, the design and implementation of a rule-based intrusion detection system for backbone network-BNIDS ( Backbone Network Intrusion Detection System) , are discussed with emphasis on the parallel cluster detection modei, packet capture mechanism and rule-based analysis engine. The results -of experiments indicate that the scalable BNIDS can do the real-time intrusion detection in a backbone network.
出处
《哈尔滨工业大学学报》
EI
CAS
CSCD
北大核心
2004年第3期273-276,共4页
Journal of Harbin Institute of Technology
基金
国家高技术研究发展计划资助项目(2002AA142020)