首页 | 本学科首页   官方微博 | 高级检索  
     

分布式入侵检测模型研究
引用本文:连一峰,戴英侠,胡艳,许一凡. 分布式入侵检测模型研究[J]. 计算机研究与发展, 2003, 40(8): 1195-1202
作者姓名:连一峰  戴英侠  胡艳  许一凡
作者单位:1. 中国科学技术大学信息科学技术学院,合肥,230027
2. 中国科学院研究生院信息安全国家重点实验室,北京,100039
基金项目:国家自然科学基金 ( 90 10 40 3 0 ),国家“九七三”重点基础研究发展规划项目 (G19990 3 5 80 1),中国科学院研究生院院长基金(yzjj2 0 0 2 0 9)
摘    要:提出了分布级别的概念对分布式入侵检测系统进行分类,并引入信息抽象级别对入侵检测中审计数据所经历的逻辑抽象层次进行表述.在对现有的层次检测模型和协作检测模型的优点和缺陷进行详细分析之后,提出了一种用于分布式入侵检测系统的层次化协作模型(HCM),并完成了相应的原型系统.该模型可以有效地综合两种现有模型的优点,在保证结点可控性和检测效率的同时提高系统的容错性和协作能力.

关 键 词:分布式入侵检测 层次化协作模型 信息抽象级别 分布级别

A Study of a Distributed Intrusion Detection Model
LIAN Yi-Feng ,DAI Ying-Xia ,HU Yan ,and XU Yi-Fan. A Study of a Distributed Intrusion Detection Model[J]. Journal of Computer Research and Development, 2003, 40(8): 1195-1202
Authors:LIAN Yi-Feng   DAI Ying-Xia   HU Yan   and XU Yi-Fan
Affiliation:LIAN Yi-Feng 1,DAI Ying-Xia 2,HU Yan 2,and XU Yi-Fan 2 1
Abstract:The concept of distribution level (DL) is proposed to classify distributed intrusion detection systems?, and information abstraction level (IAL) is introduced to characterize the logic abstraction hierarchy of audit data in the process of intrusion detection. After analyzing pros and cons of the existing hierarchical detection model and the cooperative detection model, a hierarchical cooperation model (HCM) is presented, which is applied to a distributed intrusion detection system. By integrating the advantages of the hierarchical model and the cooperative one, this model improves the ability of error-tolerance and cooperation without degradation of controllability and efficiency. Prototype of a distributed intrusion detection system based on the hierarchical cooperation model and the extended intrusion detection message exchange format(EIDMEF) is completed, which proves to be powerful as expected in detecting intrusions.
Keywords:distributed intrusion detection  hierarchical cooperation model(HCM)  information abstraction level  distribution level
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号