摘要
在分析了网络入侵检测系统主要问题的基础上,设计并实现了一个面向网络的入侵检测单元NIDU。由于采用对等式架构,NIDU具有良好的可扩展性。提出了半轮询驱动的概念,利用半轮询驱动机制降低了系统中断频率,明显提高数据采集能力;同时采用基于相关度的异常检测技术,对DoS和DDoS攻击的检测效果较现有方法有明显改善。
A network intrusion detection unit based on semi-polling driven (NIDU) was designed and implemented on the basis of analysis over the performance bottleneck. With peer architecture, NIDU has characteristic of scalability. A concept of semi-polling driven is presented. With it, interrupts frequency is reduced and the performance of capturing packet is significantly improved. NIDU uses anomaly detection technology based on similarity, which improves the detection effect of the attack of DoS and DDoS dramatically.
出处
《通信学报》
EI
CSCD
北大核心
2004年第7期146-152,共7页
Journal on Communications
基金
国家"863"计划基金资助项目(2002AA142020
2001AA147010B)
关键词
入侵检测
半轮询驱动
相关度
通信协议
intrusion detection
semi-polling
similarity
communication protocol