节点文献
基于数据分流实现高速网入侵检测的研究与实践
Research and Practice on High Speed IDS Based on Data Distribution
【摘要】 随着以太网的发展,目前基于网络的入侵检测系统已经无法适应高速增长的网络速度,提出了一种数据分流的方法,将捕获的网络数据按某种规则分流转发至多个检测设备进行处理,以达到提高整个系统的检测性能,解决高速网络下网络入侵检测设备因性能缺陷而带来的丢包问题。
【Abstract】 Nowadays,with Ethernet technology developing,the network intrusion detection system based on IP packet hasn’t been adaptive to the increasing speed of the bandwidth. This paper presents a method of distribution data to settle this problem. The network traffic is divided to several parts and transferred to different devices where data are captured and analyzed so as to improve the detection performance of system.
【基金】 国家重点基础研究发展规划“973”项目(C1999035806);中国科学院知识创新工程重大项目(KGCX1-09)
- 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2004年05期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】108