摘要
通过对现有入侵检测系统的分析 ,给出了一种基于现代高性能网络的入侵检测系统 (HPIDS)架构 ,它具有两层的检测结构 ,能较好地适应网络体系结构的变化 ,方便地引入入侵检测研究领域的最新成果 ,并能有效地集成现有的入侵检测系统 .同时 ,两层的检测结构也能提高检测效率 .系统实现的关键技术包括过载响应策略和事件相关性分析 .过载响应策略提供三种机制进行系统配置 :服务确保机制、过载识别及分流机制和自动平衡机制 ,每种机制适用于不同的环境 .
On the basis of the actuality of IDS, this paper describes a 2 hierarchy detection architecture of IDS based on high performance networks which can preferably accommodate the development of networks architecture, conveniently import the latest advances of research in intrusion detection and integrate the existing systems. At the same time, the efficiency of system detecting can be improved. The paper presents the key technologies on realizing the system as follows: response strategies of overloading and the analysis of event′s relativity. The response strategies of overloading provides three methods for system configure including assuring services, auto distributary after overloading recognition and auto balance. Every method will be used in its corresponding environment. The analysis of event′s relativity will help to improve detecting veracity.
出处
《华中科技大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2002年第3期4-6,共3页
Journal of Huazhong University of Science and Technology(Natural Science Edition)