节点文献
基于移动Agent的协同式后入侵检测技术研究
Research on Technologies of Cooperative Post Intrusion Detection Based upon Mobile Agents
【作者】 王增权;
【导师】 王慧强;
【作者基本信息】 哈尔滨工程大学 , 计算机应用技术, 2008, 博士
【摘要】 信息技术的发展直接推动了安全工具的发展。从早期的杀毒软件到后来的防火墙再到现在的入侵检测系统,人们使用的信息安全工具越来越具有主动性和智能性。当前,入侵检测系统已经成为安全防卫体系中的一个重要环节。然而目前入侵检测的研究重点集中于选择合适的数据源和数据属性、发现新的检测算法或改进现有检测算法、改进入侵检测系统的构架和扩大检测范围等方法来提高检测精度、降低误报率和漏报率等环节上,从而导致系统管理员负担过重,难以有效处理海量警报的现象。过多的误报和无关警报“淹没了”真正的攻击警报,影响入侵响应的效率和成功率,因此人们需要从新的角度来设计和实现入侵检测系统。本论文选题以应对这些挑战为出发点,试图在理清当前入侵检测问题的基础上,以多重协同机制为中心开展协同式入侵检测系统、入侵警报关联和响应追踪等问题的研究。本文试图在以下方面做一些研究:(1)分析现有的协同入侵检测模型和与之相关的技术,全面系统地阐述现有警报关联和响应追踪技术的研究进展情况,讨论当前相关技术存在的问题,引出研究协同式后入侵检测模型的必要性。(2)在分析已有入侵检测模型基础上,结合移动Agent的特点和协同机制,提出了一个基于移动Agent的协同式入侵检测系统(CooperativeIntrusion Detection System based on Mobile Agents,Co-MAIDS)框架。该系统框架在体系结构上具有防止单点失效的功能,可以避免大量数据移动带来的网络负载压力,并且能在不影响其他模块的情况下对系统模块进行增减。彼此独立的移动Agent通过相互通信协作完成复杂任务,实现系统的智能化运行。多重协同机制保证系统模块之间交互过程中的有序性,加强系统各模块的整体合作性能。(3)从揭示警报信息背后隐藏的攻击策略角度出发,提出了一种基于移动Agent的警报混合关联处理方法。该方法以二维时间和空间为轴线,将当前警报与同一时间段内发生的警报、警报前后期所发生的警报进行关联。警报关联处理采用谓词公式来表示警报前提和后果。通过对谓词公式的分解,实现不同警报之间的前提和后果进行匹配的目的,进而将警报进行关联。(4)在警报混合关联的基础上,提出了一个基于移动Agent的追踪响应策略。该策略以警报关联信息为输入,对警报信息实施了警报验证、置信度学习等警报预处理过程,并在此基础上提取有效数据包信息,依据与包标记过程相反的机理对攻击数据包的攻击路径进行追踪,实现对攻击路径的重构。(5)在以上研究内容的基础上,提出了Co-MAIDS多重协同机制的集成策略。以通信协同、警报关联协同、警报关联与入侵响应协同和入侵响应协同为核心内容,该策略整合并集成Co-MAIDS的多重协同机制。四类协同为信息、警报和响应之间架起了沟通的桥梁,确保实现系统交互的有序性和整体性。
【Abstract】 The advancement in information technology promotes the development of security tools directly. From early anti-virus softwares to the later firewalls, and even to the present intrusion detection systems, all of the information security tools become more and more active and intelligent. Nowadays, intrusion detection system has become an important tache of security defense. However, ignoring the processing of alerts, emphasis of research on intrusion detection is focused on selecting suitable data sources and data attributes, inventing new algorithms or developing current ones, enhancing detection accuracy by improving framework of intrusion detection system and enlarging detection range, as well as reducing false negative and positive, which causes too heavy burden on system manager. Mass false and unrelated alerts cover the true ones, affecting the efficiency and success rate of intrusion response. As a result, people need to design and implement intrusion detection system from a novel angle.To solve the problems of intrusion detection systems, research on the cooperative intrusion detection system, alert correlation and response traceback after analyzing the situation of current intrusion detection has been done in depth. Considering the multi-cooperative mechanism as the core, it attempts to do the following work:(1) Through analyzing present cooperative intrusion detection models as well as the related technologies, the related work of alert coorelation and response traceback is present comprehensively. Furtherly, the existing problems of current technologies are discussed. Therefor, it is important to study the cooperative post-intrusion detection model.(2) Based on analyzing of the current intrusion detection models, combining with the features of mobile agents and the corresponding cooperative mechanism, the frame structure of a cooperative intrusion detection system based on mobile agents is proposed. The system has the ability of preventing single failure, avoiding pressure of network load caused by motion of massive data, and fluctuating system modules without affecting others. Independent mobile agents accomplish complicated tasks and achieve intelligent operation of system by mutual communication. Multi-cooperative mechanism ensures the orderliness during the interaction of system modules and strengthens the whole cooperation among them.(3) To discover the attack strategy of alert information, an approach of hybrid correlated alerts based on mobile Agents is put forward. Considering time and space as the two dimensions, this method correlates current alerts with the ones happening simultaneously or the ones occurring before and after them. Predicate formulas are used to express the precondition and consequence. Matching of precondition and consequence between different alerts is achieved by decomposing the predicate formulas, based on which alerts are correlated with each other.(4) A traceback response strategy based on mobile Agents is proposed. Taking the correlated alerts as input, alert information is preprocessed by alert verification and confidence learning. Based on extracting the effective packets and the opposite mechanism of packet marking, attack path of the packet is traced and reconfigured.(5) An integration policy of multi-cooperative mechanism in Co-MAIDS is put forward based on the contents discussed above. This policy integrates multi-cooperative mechanism, having communication cooperative, alert correlation cooperative, cooperative between alert correlation and intrusion response, and intrusion response cooperative as the core. These cooperatives build bridges between information, alert and response, ensuring the orderliness and integrity of the interactions in system.
【Key words】 Cooperative; Post intrusion detection; Mobile Agent; Alert correlation; Traceback response;