【24h】

Intrusion Detection Technology Research based High-Speed Network

机译:基于入侵检测技术的高速网络研究

获取原文
获取原文并翻译 | 示例

摘要

Most existing Distributed Intrusion Detection Systems (DIDS) take a master/slave or principal/subordinate structure, where a master or principal station plays important role in intrusion detection. This paper presents a framework of Peer-to-Peer Distributed Network Intrusion Detection System (P2P DNIDS) based on the experience gained in a project sponsored by 30th Research Institute of Administration of Information Industry. In a P2P DNIDS all the IDS stations or sub-systems have same detection capability and perform similar functions and in case of single subsystem failure other subsystem can take over its responsibility and makes the whole system more robust and flexible. With the increase in the network truck speed from M bps to G bps, intrusion detection systems have to face the packet leaking problem, in which part of the incoming packets are unchecked and have to let them bypass the detection routine for inadequate checking strategy or processing speed. This paper handles this problem by introducing various techniques and tactics such as load balancing, increasing checking coverage, and better matching algorithms.
机译:现有的大多数分布式入侵检测系统(DIDS)都采用主/从或主体/从属结构,其中,主站或主体在入侵检测中起着重要的作用。本文基于由信息产业管理局第30研究所赞助的项目中获得的经验,提出了对等分布式网络入侵检测系统(P2P DNIDS)的框架。在P2P DNIDS中,所有IDS站或子系统都具有相同的检测能力并执行类似的功能,并且在单个子系统发生故障的情况下,其他子系统可以承担起其责任,并使整个系统更加健壮和灵活。随着网络卡车速度从M bps增长到G bps,入侵检测系统不得不面对数据包泄漏问题,其中部分传入数据包未经检查,必须让它们绕过检测例程以进行不充分的检查策略或处理。速度。本文通过介绍各种技术和策略来解决此问题,例如负载平衡,增加检查范围和更好的匹配算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号