作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (5): 150-152. doi: 10.3969/j.issn.1000-3428.2008.05.052

• 安全技术 • 上一篇    下一篇

基于Agent的分布式协作入侵检测系统

林昭文,赵毅德,马 严   

  1. (北京邮电大学计算机科学与技术学院,北京 100876)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-03-05 发布日期:2008-03-05

Agent-based Distributed Cooperative Intrusion Detection System

LIN Zhao-wen, ZHAO Yi-de, MA Yan   

  1. (School of Computer Science and Technology, Beijing University of Posts and Telecommunications, Beijing 100876)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-03-05 Published:2008-03-05

摘要: 分析了当前入侵检测系统及其存在的问题,提出一个基于Agent的分布式协作检测模型(ADCM),给出其原型系统。该模型通过逻辑检测域(LDD)之间的协作通信,完成对新型分布式攻击的检测。实验证明ADCM可以有效地检测出具有一定隐蔽性的、分布式的协作攻击。

关键词: 入侵检测, 分布式攻击, 代理, 协作模型

Abstract: Most of intrusion detection systems nowadays are not really distributed systems which cannot detect the distributed or cooperative attacks effectively. This paper proposes an Agent-based Distributed Cooperative Model(ADCM), which implements cooperative intrusion detection through efficient, normative event messages exchange among Logic Detection Domains(LDDs). It describes the functions of entities, defines the communication mechanisms, and designs some detection Agents which are independent separately, while they can communicate and cooperate with one another to take actions. Results show that ADCM can improve the ability of detecting stealthily and distributed cooperative attacks.

Key words: intrusion detection, distributed attack, Agent, cooperative model

中图分类号: