摘要
随着以太网的发展,目前基于网络的入侵检测系统已经无法适应高速增长的网络速度,提出了一种数据分流的方法,将捕获的网络数据按某种规则分流转发至多个检测设备进行处理,以达到提高整个系统的检测性能,解决高速网络下网络入侵检测设备因性能缺陷而带来的丢包问题。
Nowadays,with Ethernet technology developing,the network intrusion detection system based on IP packet hasn't been adaptive to the increasing speed of the bandwidth. This paper presents a method of distribution data to settle this problem. The network traffic is divided to several parts and transferred to different devices where data are captured and analyzed so as to improve the detection performance of system.
出处
《计算机应用研究》
CSCD
北大核心
2004年第5期149-151,共3页
Application Research of Computers
基金
国家重点基础研究发展规划"973"项目(C1999035806)
中国科学院知识创新工程重大项目(KGCX1-09)
关键词
入侵检测
高速网
数据分流
NIDS
High- speed Network
Data Distribution