节点文献
基于Agent与数据挖掘的分布式入侵检测系统
Distributed Intrusion Detection System Based on Data Mining and Agent
【摘要】 针对目前计算机入侵检测系统中存在的不足,文中构建了一个基于Agent和数据挖掘技术的分布式入侵检测系统。这个系统引入移动Agent使入侵检测较好地适应了分布式的环境,采用数据挖掘技术使检测系统能够更加快速有效地发现入侵行为,明显地提高了检测系统的实时性。它还把误用检测和异常检测溶为一体,把基于主机和基于网络的入侵检测进行有机结合,具有良好的可扩展性、灵活性、鲁棒性、安全性、实时性、自适应性和检测的准确性。
【Abstract】 Aiming at the defects exiting in the present intrusion detection system,proposes to construct a distributed IDS framework based on Agent and the technology of data mining, which introduces mobile Agents that make the IDS system well adapt the distributed environment.And adopts data mining technology that makes the IDS system be able to find the intrusions faster and more efficient.Accordingly the realtime of the IDS has been improved .This IDS system makes misuse-detection and anomaly-detection into a whole and integrates IDS based on computer with that based on network.It has such advantages as expansibility, flexibility, robust, security, realtime, self-adaptability, and better detecting accuracy.
- 【文献出处】 微机发展 ,Microcomputer Development , 编辑部邮箱 ,2004年03期
- 【分类号】TP39308
- 【被引频次】7
- 【下载频次】115