期刊文献+

高速网络下的分布式实时入侵检测系统 被引量:28

A Distributed Real-Time Intrusion Detection System for High-Speed Network
下载PDF
导出
摘要 随着网络技术的飞速发展 ,网络安全问题日益突出 网络入侵检测系统需要处理大量的数据 ,处理能力的缺乏会引起入侵事件的漏报 ,提高入侵检测系统的处理能力是目前急需解决的关键问题 DRTIDS(distributedreal timeintru siondetectionsystemforhigh speednetworks)是一个由单个分析节点和多个探测节点组成的、工作在高速网络下的分布式网络入侵检测系统 DRTIDS的分析节点执行基于网络主机的流量分配策略 ,保证尽可能地平衡分配网络流量 。 Now centralized solutions of real time IDS (intrusion detection system) in high speed network have reached their limits because of several technical difficulties encountered in keeping pace with the increasing network speed and communication complexity between applications A DRTIDS (distributed real time intrusion detection system) is proposed, which is centered around a load balance traffic slicing mechanism that ramifies the total packet stream into branches of manageable size and guarantees that each branch contains all the evidence necessary to determine a specific attack With the traffic partitioning done in the analyzer node, multiple sensors can manage sub packet stream simultaneously This approach is described in details
出处 《计算机研究与发展》 EI CSCD 北大核心 2004年第4期667-673,共7页 Journal of Computer Research and Development
基金 国家"八六三"高技术研究发展计划基金项目 (2 0 0 1AA14 2 0 10 )
关键词 网络入侵检测系统 分布式结构 高速网络 平衡的流量分配策略 实时分析 networks intrusion detection system distributed architecture high speed networks load balance slicing mechanism real time analysis
  • 相关文献

参考文献9

  • 1[1]V Paxson. Bro: A system for detecting network intruders in real-time. USENIX Association, 1998, 1(1): 31~51
  • 2[2]K Huang, Z W Xu. Scalable Parallel Computing. Hongkong: China Machine Press, 2000
  • 3[3]D D Clark, S Shenker, L X Zhang. Supporting real-time applications in an integrated services packet network architecture and mechanism. Proc of ACM SIGCOMM, Baltimore, Maryland, USA, 1992
  • 4[4]A Demers, S Keshavt, S Shenker. Analysis and simulation of fair queuing algorithm. Proc of ACM SIGCOMM, Austin, TX, USA, 1989
  • 5[5]G Varghese, M Shreedar. Efficient fair queuing using deficit round robin. Proc of ACM SIGCOMM, Cambridge, MA, USA, 1995
  • 6[6]S Floyd, V Jacobson. Link-sharing and resource management models for packet network. IEEE/ACM Trans on Networking, 1995, 3(4): 365~386
  • 7[7]I Stoica, S Shenker, H Zhang. Core-stateless fair queuing: Achieving approximately fair bandwidth allocations in high speed networks. Computer Communication Review, 1998, 28(4): 118~130
  • 8[8]C Kruegel, F Valeur, G Vigna et al. Stateful intrusion detection for high-speed networks. In: Proc of the 2002 IEEE Symp on Security and Privacy. Los Alamitos, California: IEEE Computer Society Press, 2002. 285~294
  • 9[9]N F Puketza, K Zhang, M Chung et al. A methodology for testing intrusion detection systems. IEEE Trans on Software Engineering, 1996, 22(10): 719~729

同被引文献131

引证文献28

二级引证文献61

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部