节点文献

分布式入侵检测系统安全通信机制研究

Research on safe communication mechanism of distributed IDS

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 蔡伟鸿刘震

【Author】 CAI Wei-hong,LIU Zhen(Department of Computer Science,Shantou University,Shantou 515063,China)

【机构】 汕头大学计算机系汕头大学计算机系 广东汕头515063广东汕头515063

【摘要】 现有的IDS多采用集中统一收集和分析数据的体系结构,这种体系结构的入侵检测系统存在单点失效和可扩展性问题。论文在分析现有分布式入侵检测系统结构基础上,提出了一个基于任务分发机制的分布式入侵检测系统体系架构。同时为了保证各Agent通信的信息保密性和完整性,重点研究设计了基于XML的信息交换格式,并进而设计了一个基于PKI基础设施,ECC和DES对称、非对称加密技术的安全信息交互协议框架,可以有效地保证各Agent通信安全。

【Abstract】 In the current IDS,the unification of collect and analysis data is the most common case,and apparently it has the single node invalidation and expansibility problem.A mission allocated distributed IDS framework was firstly propased.On the other hand,in order to keep the information exchange secret among the agents,a message exchange format based on the XML technology and message ex-change protocol based on the PKI and ECC、DES encryption were designed,which could effectively ensure the communication safe and integrated.

【关键词】 入侵检测XMLPKIECC信息交互协议
【Key words】 intrusion detectionXMLPKIECCmessage exchange protocol
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2006年04期
  • 【分类号】TP393.08
  • 【被引频次】14
  • 【下载频次】172
节点文献中: 

本文链接的文献网络图示:

本文的引文网络