摘要
基于关联和代理的分布式入侵检测模型,提出了一种分布式入侵检测系统的通信机制设计方案。其中通信Agent间的消息交换格式参照IDMEF标准,给出其消息内容详细设计,并根据需求扩充了警报数据XML描述;汇聚点通信Agent中使用基于subscription通信模式减少了系统的通信开销,具体描述了subscription的逻辑结构实现;还在通信机制中采用SSL技术较好解决了数据传输的安全问题。
According to the distributed intrusion detection model based on correlation and Agent, a kind of communication mechanism was proposed. With reference to the Intrusion Detection Message Exchange Format (IDMEF), a detailed message system was described for communication Agent, and in accordance with demand expanded XML description. Using the subscription coinmunicatiorts model in order to reduce the overhead of communication, subscription logic framework was described. Based on SSL, a security communication mechanism can meet the demand of the distributed intrusion detection system.
出处
《计算机应用》
CSCD
北大核心
2008年第4期843-845,共3页
journal of Computer Applications
基金
国家973面上项目(2006CB303006)
国家973前期研究项目(2007CB316505)
江西师范大学博士基金项目
关键词
分布式入侵检测
代理
通信机制
入侵检测消息交换格式
XML
distributed intrusion detection
Agent
communication mechanism
Intrusion Detection Message Exchange Format (IDMEF)
XML