节点文献

利用Netfilter实现NIDS集群的研究和实践

Research and Implementation of NIDS Cluster via Netfilter

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 杨彬李雪莹陈宇许榕生

【Author】 YANG Bin1, LI Xueying2,3, CHEN Yu2, XU Rongsheng2 (1.Graduate School of USTC, Beijing 100039;2.Computing Center, IHEP, CAS, Beijing 100039; 3. Network Information Center, Institute of Medical Information, Academy of Military Medical Sciences, Beijing 100850)

【机构】 中国科学技术大学研究生院,中国科学院高能物理所计算中心,中国科学院高能物理所计算中心,中国科学院高能物理所计算中心 北京100039,北京100039军事医学科学院医学情报研究所网络信息中心,北京100850,北京100039,北京100039

【摘要】 目前基于网络的入侵检测系统(NIDS)面临普通单机检测设备的数据包处理能力不能适应网络带宽发展需求的问题,该文介绍了利用NIDS集群在高速网络环境下实现入侵检测的方法。根据NIDS集群的特点利用Linux内核中Netfilter模块实现了数据包基于分流转发和会话的动态负载均衡。并通过使用基于Linux操作系统的IDS负载均衡器实现了NIDS集群在高速网络环境下的入侵检测。

【Abstract】 s Currently, the problem occurred in the network based IDS is that the processing packets ability of normal PC is not adaptive to the requirement of network bandwidth developing. This paper introduces one kind of method of intrusion detection in high-speed network environment via NIDS cluster. It implements distribution and conversation based dynamic load balance of packet via netfilter module in Linux kernel according to the characteristics of NIDS cluster. So it implements intrusion detection in high-speed network environment by building NIDS cluster via Linux based IDS load balance.

【关键词】 Netfilter钩子基于网络的入侵检测系统集群负载均衡哈希
【Key words】 NetfilterHookNIDSClusterLoad balanceHash
【基金】 国家重点基础研究发展规划“973”项目(G1999035806);中国科学院知识创新工程重大项目(KJCX1-09)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2003年15期
  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】75
节点文献中: 

本文链接的文献网络图示:

本文的引文网络