When traditional Intrusion Detection System(IDS) is used to detect and analyze the great flow data transfer in high-speed network,it usually causes the computation bottleneck. This paper presents a new Mobile Agent Di...When traditional Intrusion Detection System(IDS) is used to detect and analyze the great flow data transfer in high-speed network,it usually causes the computation bottleneck. This paper presents a new Mobile Agent Distributed IDS(MADIDS) system based on the mobile agents. This system is specifically designed to process the great flow data transfer in high-speed network. In MADIDS,the agents that are set at each node process the data transfer by distributed computation architecture. Meanwhile by using the reconfiguration quality of the mobile agents ,the load balance of distributed computation can be dynamically implemented to gain the high-performance computing ability. This ability makes the detecting and analyzing of high-speed network possible. MADIDS can effectively solve the detection and analysis performance bottleneck caused by the great flow data transfer in high-speed network. It enhances the performance of IDS in high-speed network. In this paper,we construct the infrastructure and theoretical model of MADIDS,and the deficiencies of MADIDS and future research work are also indicated.展开更多
详细介绍了在Linux环境下基于规则的分布式网络入侵检测系统NetNumen.同现有的网络入侵检测系统相比,NetNumen将异常检测(检测包到达频度的异常)和特征检测(检测特定攻击和攻击工具的固有特征)有机地结合起来,对DoS(denial of service),...详细介绍了在Linux环境下基于规则的分布式网络入侵检测系统NetNumen.同现有的网络入侵检测系统相比,NetNumen将异常检测(检测包到达频度的异常)和特征检测(检测特定攻击和攻击工具的固有特征)有机地结合起来,对DoS(denial of service),DdoS(distributed denial of service)攻击的检测效果较现有方法有明显的改善.展开更多
文摘When traditional Intrusion Detection System(IDS) is used to detect and analyze the great flow data transfer in high-speed network,it usually causes the computation bottleneck. This paper presents a new Mobile Agent Distributed IDS(MADIDS) system based on the mobile agents. This system is specifically designed to process the great flow data transfer in high-speed network. In MADIDS,the agents that are set at each node process the data transfer by distributed computation architecture. Meanwhile by using the reconfiguration quality of the mobile agents ,the load balance of distributed computation can be dynamically implemented to gain the high-performance computing ability. This ability makes the detecting and analyzing of high-speed network possible. MADIDS can effectively solve the detection and analysis performance bottleneck caused by the great flow data transfer in high-speed network. It enhances the performance of IDS in high-speed network. In this paper,we construct the infrastructure and theoretical model of MADIDS,and the deficiencies of MADIDS and future research work are also indicated.
文摘详细介绍了在Linux环境下基于规则的分布式网络入侵检测系统NetNumen.同现有的网络入侵检测系统相比,NetNumen将异常检测(检测包到达频度的异常)和特征检测(检测特定攻击和攻击工具的固有特征)有机地结合起来,对DoS(denial of service),DdoS(distributed denial of service)攻击的检测效果较现有方法有明显的改善.