摘要
为了增强IDS(IntrusionDetectionSystem)在广域网中的健壮性,本文在对几种典型的入侵检测模型进行分析的基础上,提出了抗攻击的基于移动代理的分布式入侵检测模型(MobileAgentBasedDistributedIntrusionDetectionSystemModel,MABDIDSM).MABDIDSM利用移动代理(mobileagent)在各局域网的控制台之间做环行移动,将各控制台上的入侵事件收集到管理中心进行综合分析处理.如果管理中心受到攻击,移动代理能够在剩余的控制台中选出新的管理中心,因此MAB-DIDSM在广域网范围内具有较强的抗攻击能力.
To improve IDS' (Intrution Detection System) robustness in WAN,after analyzing several typical IDS models, MABDIDSM (Mobile Agent Based Distributed Intrusion Detection System Model) protecting from attack is presented in this paper. Mobile agent circles among the consoles in every LAN and collects intrusion events to manager center in MABDIDSM. These intrusion events are analyzed and processed in manager center. If manager center is paralyzed, mobile agent can elect new manager center from remainder consoles. Thus MABDIDSM is equipped with better capacity of protecting from attack in WAN.
出处
《小型微型计算机系统》
CSCD
北大核心
2005年第9期1500-1506,共7页
Journal of Chinese Computer Systems
基金
国家"八六三"高科技发展计划项目(2001AA142010)资助.
关键词
攻击
移动代理
模型
attack
mobile agent
model