节点文献

基于移动agent技术的入侵检测系统的设计与实现

【作者】 金飞蔡

【导师】 黄迪明;

【作者基本信息】 电子科技大学 , 计算机应用技术, 2004, 硕士

【摘要】 入侵检测技术是目前网络安全领域的一个研究热点,虽然目前入侵检测技术已经有了长足的进步,开发出了许多针对不同需要的产品,但传统的入侵检测系统仍然存在一些缺陷,例如在分布性,智能性,灵活性,效率方面都存在不尽如人意的地方。随着计算机智能化和网络化进程的发展,Agent技术迅速崛起并且得到了广泛应用,移动Agent技术是为解决复杂、动态、分布式智能应用而提出的一种全新的计算手段,本论文提出并深入研究了一个基于移动智能体技术的入侵检测系统的体系结构。该体系结构将移动智能体技术应用于入侵检测,解决了传统的集中式入侵检测系统的缺陷,将任务处理和数据分布到网络各个结点上,自动适应复杂多变的网络环境,能通过自我学习、自我进化提高系统的入侵检测能力,能充分利用网络资源协同完成入侵检测任务。该体系结构是一种混合形结构:一方面,该结构同时利用基于主机和基于网络的数据源,使得IDS能收集到更加全面的信息;另一方面,该结构同时使用了异常检测技术和误用检测技术,既能检测已知的攻击模式,又能发现新的攻击模式。在系统的具体实现中,本文对异常检测技术做了深入的研究,并且把他应用到了相应的检测模块。本文首先详细介绍了入侵检测技术和移动agent技术,然后对本系统做了需求分析,确定了系统的性能要求以及本系统的开发环境和应用环境,并且对系统的测试做了简要的介绍。本文详细论述了所提出的入侵检测系统体系结构的主要特点及其采用的主要技术,并依据此结构设计了一个入侵检测原型系统。论文详细论述了整个原型系统的各功能模块。本文还重点介绍了两种异常检测的方法,一种是针对主机数据源提出的基于隐马尔可夫模型的异常检测,一种是针对网络数据源提出的基于服务特征的异常检测,这两种异常检测方法的使用有效地提高了整个系统的检测能力,极大地增强了系统的自适应能力,在不需要任何攻击领域知识的情况下,能够很好地检测出未知的攻击。

【Abstract】 Intrusion detection technology has become an important research subject in the field of network security. The research of intrusion detection has grown considerably nowadays, and there are a large number of intrusion detection systems have been developed to address different needs. However, the traditional intrusion detection systems have some shortcomings in certain aspects, such as distribute, intelligent, flexibility, efficiency and so on.The IDS proposed in this thesis is based on mobile agent technique, by which IDS distributes data and tasks to the nodes in the networks. Thus IDS can make best use of compute capability and resources of the networks, which covers the shortage of conventional centralized intrusion detection approach. Moreover, this new architecture enables IDS to enhance detection capability and adaptability to intricate network environment through self-study and evolution. To achieve better accuracy, the architecture adopts security audit data gathered from both host and network. To enable IDS to detect both known and unknown intrusion model, the architecture adopts a blend frame that makes use of both misuse detection approach and anomaly detection approach. At first of the dissertation, the technology of IDS and mobile agent has been presented in detail. Then, the dissertation analyzes the requirement of the system, and confirms the development’s environment. Secondly, It introduces the architecture in detail. In the end, another highlight of the architecture is introduction of anomaly detection technique.

【关键词】 入侵检测移动agent隐马尔可夫模型异常检测
【Key words】 IDSMobile AgentHMMAnomaly Detection
  • 【分类号】TP393.08
  • 【被引频次】5
  • 【下载频次】204
节点文献中: