节点文献
利用Netfilter实现NIDS集群的研究和实践
Research and Implementation of NIDS Cluster via Netfilter
【摘要】 目前基于网络的入侵检测系统(NIDS)面临普通单机检测设备的数据包处理能力不能适应网络带宽发展需求的问题,该文介绍了利用NIDS集群在高速网络环境下实现入侵检测的方法。根据NIDS集群的特点利用Linux内核中Netfilter模块实现了数据包基于分流转发和会话的动态负载均衡。并通过使用基于Linux操作系统的IDS负载均衡器实现了NIDS集群在高速网络环境下的入侵检测。
【Abstract】 s Currently, the problem occurred in the network based IDS is that the processing packets ability of normal PC is not adaptive to the requirement of network bandwidth developing. This paper introduces one kind of method of intrusion detection in high-speed network environment via NIDS cluster. It implements distribution and conversation based dynamic load balance of packet via netfilter module in Linux kernel according to the characteristics of NIDS cluster. So it implements intrusion detection in high-speed network environment by building NIDS cluster via Linux based IDS load balance.
【Key words】 Netfilter; Hook; NIDS; Cluster; Load balance; Hash;
- 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2003年15期
- 【分类号】TP393.08
- 【被引频次】4
- 【下载频次】75