首页 | 本学科首页   官方微博 | 高级检索  
     

分布式网络入侵检测系统NetNumen的设计与实现
引用本文:李旺,吴礼发,胡谷雨.分布式网络入侵检测系统NetNumen的设计与实现[J].软件学报,2002,13(8):1723-1728.
作者姓名:李旺  吴礼发  胡谷雨
作者单位:1. 解放军理工大学,通信工程学院,电信工程系,江苏,南京,210016
2. 解放军理工大学,指挥自动化学院,计算机教研室,江苏,南京,210016
基金项目:国家863高科技发展计划资助项目(863-306-ZD08-01-2)
摘    要:详细介绍了在Linux环境下基于规则的分布式网络入侵检测系统NetNumen.同现有的网络入侵检测系统相比,NetNumen将异常检测(检测包到达频度的异常)和特征检测(检测特定攻击和攻击工具的固有特征)有机地结合起来,对DoS(denial of service),DdoS(distributed denial of service)攻击的检测效果较现有方法有明显的改善.

关 键 词:入侵检测  入侵检测系统  网络安全  DoS(denial  of  service)  DdoS(distributed  denial  of  service)
文章编号:1000-9825/2002/13(08)1723-06
收稿时间:2001/2/12 0:00:00
修稿时间:6/7/2001 12:00:00 AM

Design and Implementation of Distributed Intrusion Detection System NetNumen
LI Wang,WU Li-fa and HU Gu-yu.Design and Implementation of Distributed Intrusion Detection System NetNumen[J].Journal of Software,2002,13(8):1723-1728.
Authors:LI Wang  WU Li-fa and HU Gu-yu
Abstract:A rule-based distributed intrusion detection system NetNumen is presented in Linux in this paper. Compared with the existing network-based intrusion detection system, NetNumen combines anomaly detections (detecting the anomaly frequency of packets?arriving) with signature detections (detecting the immanent characters of specialized attack and attack instrument), which improves the detection effect of the attack of DoS (denial of service)and DdoS (distributed denial of service) dramatically.
Keywords:intrusion detection  IDS (intrusion detection system)  network security  DoS (denial of service)  DdoS (distributed denial of service)
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号