作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (1): 142-144. doi: 10.3969/j.issn.1000-3428.2008.01.048

• 安全技术 • 上一篇    下一篇

DIDS监视代理间数据融合算法的设计与实现

李阿丽1,陈艳芳2,张福增1,李凌云1   

  1. (1. 鲁东大学计算机科学与技术学院,烟台 264025;2. 华为技术有限公司,深圳 518129)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-01-05 发布日期:2008-01-05

Design and Realization of Data Fusion Arithmetic Between Monitor Agents in DIDS

LI A-li1, CHEN Yan-fang2, ZHANG Fu-zeng1, LI Ling-yun1   

  1. (1. School of Computer Science and Technology, Ludong University, Yantai 264025; 2. Huawei Technologies Co., Shenzhen 518129)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-01-05 Published:2008-01-05

摘要: 提出并实现用于分布式入侵检测系统中多监视代理之间协同检测的数据融合算法,实验证明该算法可以在0.07 s~1 s之内检测出SYN洪水、Smurf、Land等多种分布式拒绝服务攻击,并及时采取响应措施,阻断攻击者的网络连接。该算法建立在对多数据源的数据分析基础之上,提高了入侵检测的准确性,克服了路由访问控制列表过滤的局限性,可以实现在不影响网络正常运行情况下的实时检测与报警功能。

关键词: 分布式入侵检测, 监视代理, 数据融合

Abstract: The paper provides and realizes the data fusion arithmetic used among the monitor agents in Distributed Intrusion Detection System (DDIS), then testifies that the arithmetic can detect many distributed denial attacks such as SYN flood, Smurf, Land etc in 0.07 s~1 s and take instant countermeasures to block intrusive connections. Based on the analysis of multi-data of many machines, so the arithmetic advances the exactness of intrusion detection largely, overcomes the localization of the traditional detect method of router access control list, and basically realizes detect and alert function without affecting the normal running of the network.

Key words: distributed intrusion detection, monitor agent, data fusion

中图分类号: