摘要
提出并实现用于分布式入侵检测系统中多监视代理之间协同检测的数据融合算法,实验证明该算法可以在0.07 s~1s之内检测出SYN洪水、Smurf、Land等多种分布式拒绝服务攻击,并及时采取响应措施,阻断攻击者的网络连接。该算法建立在对多数据源的数据分析基础之上,提高了入侵检测的准确性,克服了路由访问控制列表过滤的局限性,可以实现在不影响网络正常运行情况下的实时检测与报警功能。
The paper provides and realizes the data fusion arithmetic used among the monitor agents in Distributed Intrusion Detection System (DDIS), then testifies that the arithmetic can detect many distributed denial attacks such as SYN flood, Smurf, Land etc in 0.07 s- 1 s and take instant countermeasures to block intrusive connections. Based on the analysis of multi-data of many machines, so the arithmetic advances the exactness of intrusion detection largely, overcomes the localization of the traditional detect method of router access control list, and basically realizes detect and alert function without affecting the normal running of the network.
出处
《计算机工程》
CAS
CSCD
北大核心
2008年第1期142-144,共3页
Computer Engineering
关键词
分布式入侵检测
监视代理
数据融合
distributed intrusion detection
monitor agent
data fusion