作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (21): 126-128. doi: 10.3969/j.issn.1000-3428.2008.21.046

• 安全技术 • 上一篇    下一篇

基于异构机群的高速网络入侵检测系统

杨 锋,钟 诚,尹梦晓   

  1. (广西大学计算机与电子信息学院,南宁 530004)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-11-05 发布日期:2008-11-05

High-speed Network Intrusion Detection System Based on Heterogeneous Cluster

YANG Feng, ZHONG Cheng, YIN Meng-xiao   

  1. (School of Computer and Electronics Information, Guangxi University, Nanning 530004)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-11-05 Published:2008-11-05

摘要: 结合异构机群系统,提出一种基于双向驱动的分流算法,将高速数据流分为多个子数据流,把子数据流交由异构机群系统中最合适的节点处理,实现基于异构机群的高速网络入侵检测系统。实验结果表明,该系统保证了某时间段内具有相同源或目的地址的所有数据包发向同一个后端IDS引擎进行检测,能在高速网络环境下保持高检测率,并有效解决负载均衡问题。

关键词: 入侵检测, 异构机群, 负载均衡

Abstract: This paper presents a diffluent algorithm based on bidirectional drive by applying heterogeneous cluster computing systems. It divides high traffic into several data streams, sends them to the most suited node in heterogeneous cluster computing systems, and implements the high-speed network intrusion detection system based on heterogeneous cluster. Experimental results show that this system can ensure that all data packages which take on the same source or destination with period of time are sent to the same IDS analysis engines, keep high detection rate on high-speed network and resolve the load balancing problem effectively.

Key words: intrusion detection, heterogeneous cluster, load balancing

中图分类号: