Computer Engineering and Applications ›› 2011, Vol. 47 ›› Issue (35): 95-98.

• 网络、通信、安全 • Previous Articles     Next Articles

Design and implementation of a kind of distributed IDS based on intelligent agent

WANG Yiran1,HUANG Yuda2,3,ZHANG Xingang4   

  1. 1.Department of Computer Science,Zhoukou Normal University,Zhoukou,Henan 466001,China
    2.Department of Information Engineering,Zhoukou Vocational Technology College,Zhoukou,Henan 466000,China
    3.School of Computer Science and Technology,Southwest University of Science and Technology,Mianyang,Sichuan 621000,China
    4.School of Computer and Information Technology,Nanyang Normal University,Nanyang,Henan 473061,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-12-11 Published:2011-12-11

一种基于智能主体的分布式入侵检测系统设计与实现

王迤冉1,黄宇达2,3,张新刚4   

  1. 1.周口师范学院 计算机科学系,河南 周口 466001
    2.周口职业技术学院 信息工程系,河南 周口 466000
    3.西南科技大学 计算机科学与技术学院,四川 绵阳 621000
    4.南阳师范学院 计算机学院,河南 南阳 473061

Abstract: Aiming at the problem of single point invalidation and the bottleneck of treatment ability in distributed IDS,a new distributed IDS based on intelligent agent is designed and implemented.The system uses the distributed architecture based on kinds of intelligent agents,and assembles these intelligent agents with the functional components from functional components pools to meet the needs of the intrusion detection.During treatment of the conjunctive information of invasion attack features,IADIDS reduces the complexity of intrusion detection algorithms and improves the intrusion detection capabilities.Through the system simulation,intrusion detection accuracy rate reaches to 96%,and the results show that its performance is better than the other intrusion detection systems.

Key words: intrusion detection, intelligent agent, network security

摘要: 针对分布式入侵检测系统存在的单点失效和处理能力瓶颈问题,设计并实现了一种基于智能主体的分布式入侵检测系统。该系统基于多种智能主体的分布式结构,在进行入侵检测时,采用按需装配的方式,通过对入侵攻击特征信息中的关联信息进行处理,降低了入侵检测算法的复杂度,提高了系统的入侵检测能力。通过对该系统的仿真,入侵攻击检测准确率达到96%,结果表明其性能要好于其他的入侵检测系统。

关键词: 入侵检测, 智能主体, 网络安全