J4

• 计算机 • 上一篇    下一篇

一种基于代理和蜜罐技术的分布式入侵检测系统模型

库宇1, 胡亮1, 张晓晖2   

  1. 1. 吉林大学 计算机科学与技术学院, 长春 130012; 2. 长春市公安消防支队, 长春 130062
  • 收稿日期:2006-07-18 修回日期:1900-01-01 出版日期:2007-05-26 发布日期:2007-05-26
  • 通讯作者: 胡亮

An Autonomous Distributed Intrusion Detection SystemBased on Agent and Honeypot

KU Yu1, HU Liang1, ZHANG Xiaohui2   

  1. 1. College of Computer Science and Technology, Jilin University,Changchun 130012, China;2. Changchun Public Security Bureau, Changchun 130062, China
  • Received:2006-07-18 Revised:1900-01-01 Online:2007-05-26 Published:2007-05-26
  • Contact: HU Liang

摘要: 提出一种基于Agent的自适应分布式入侵检测系统模型,以解决大多数传统的、 采用集中式的分析引擎的入侵检测系统误报率较高且缺乏自适应性的缺点; 同时, 针对现有大多数模型具有较高漏报率的问题, 提出一种基于蜜罐分布式的入侵检测系统模型.

关键词: 网络安全, 入侵检测, 代理, 蜜罐

Abstract: Most traditional intrusion detection systems adopt the analysis engine of the concentrating type, so it is already difficult for them to meet the extensive security demand of the distributed network environment. An autonomousagentbased adaptive distributed intrusion detection system was proposed to solve these problems. A honeypotbased distributed intrusion detection system was proposed to solve the higher rate of false negatives in most models. Moreover a detail description was given to the architecture and work mechanism of the model, and the character of the model was analyzed.

Key words: network security, intrusion detection, agent, honeypot

中图分类号: 

  • TP393.08