摘要
提出了一种基于多代理(Agent)的入侵检测数据收集模型。该模型建立在基于多代理的系统安全体系结构之上,与系统其他安全机制相结合,根据需要灵活部署代理,利用代理捕捉入侵和可疑事件,同时实现基于主机和基于网络的数据收集,为入侵检测系统(IDS)提供尽可能及时、完整和准确的数据。
This paper considers a multi-agent model of a computer networks security system and describes a new approach to collecting real-time information from the hosts and the network to be protected by agents and forwarding the data to an IDS. After combining with other security mechanisms like access control, authentication and identification system, the proposed model can complement traditional network-based and host-based data collection methods and provide the data for IDS duly,completely and correctly.
出处
《计算机应用研究》
CSCD
北大核心
2004年第1期103-104,108,共3页
Application Research of Computers
基金
国家自然科学基金资助项目(90204012)
关键词
多代理
入侵检测
Multi-Agent
Intrusion Detection