作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (06): 139-140. doi: 10.3969/j.issn.1000-3428.2007.06.049

• 安全技术 • 上一篇    下一篇

分布式自治型入侵检测系统研究

陈蜀宇,吴庆佺,周辉毅   

  1. (重庆大学计算机学院,重庆 400030)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-03-20 发布日期:2007-03-20

Research of Autonomous Model of Distributed Intrusion Detection System

CHEN Shuyu, WU Qingquan, ZHOU Huiyi   

  1. (College of Computer, Chongqing University, Chongqing 400030)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-03-20 Published:2007-03-20

摘要: 传统分布式入侵检测系统大都采用多层次型结构,存在层次控制复杂及通信瓶颈等问题。该文提出了一种分布式自治型入侵检测系统,采用2层结构框架减少了控制层次,通过结合了协议分析和模式匹配技术的自治性检测节点来实现分布式检测,用自定义通信协议及标准SSL协议来保障系统内部通信安全,通过B/S模式实现在任意节点浏览告警信息,方便了用户使用。

关键词: 入侵检测系统, 分布式, 自治型

Abstract: The traditional distributed intrusion detection systems mostly use multilayer architecture, which results in complicated management and communicational bottleneck. This article introduces an autonomous model of distributed intrusion detection system. It has only two layers so it can reduce the complicate of layer control. It makes up of autonomous detection node, which integrates the protocol analysis technology and the pattern matching technology to achieve distributed intrusion detection. It uses user-defined protocol and the standard SSL protocol to ensure security of the communications within the whole system. For the convenience of the custom, it can browse the alarm in any detection node by browse/server model.

Key words: Intrusion detection system, Distributed, Autonomous model