论文部分内容阅读
入侵检测系统可以对系统或网络资源进行实时检测 ,及时发现闯入系统或网络的入侵者 ,也可预防合法用户对资源的误操作 ,它是P2 DR (PolicyProtectionDetectionResponse ,简称P2 DR)安全模型的一个重要组成部分。本文首先介绍了入侵检测系统的研究难点与目前存在的问题 ,然后重点介绍我们所研制的基于代理的网络入侵检测系统的体系结构、总体设计与实现、关键技术以及系统的特色。目前该系统在入侵检测系统的体系结构、入侵检测技术、响应与恢复策略、分布式代理(Agent)技术、基于代理的入侵检测知识库等方面有创新和突破
Intrusion detection system can detect the system or network resources in real time, detect intruders who break into the system or network in time, and prevent misuse of resources by authorized users. It is one of the P2 DR (P2 Protection Policy Security Protocol P2 P2) security model An important part of. In this paper, the research difficulties and the existing problems of intrusion detection system are introduced firstly, and then the architecture, overall design and implementation, key technologies and system features of the agent-based network intrusion detection system that we developed are emphatically introduced. At present, the system has some innovations and breakthroughs in the architecture of intrusion detection system, intrusion detection technology, response and recovery strategy, distributed agent (Agent) technology, agent-based intrusion detection knowledge base