【24h】

Agent-Based Distributed Intrusion Alert System

机译:基于代理的分布式入侵警报系统

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection for computer systems is a key problem in today's networked society. Current distributed intrusion detection systems (IDSs) are not fully distributed as most of them centrally analyze data collected from distributed nodes resulting in a single point of failure. Increasingly, researchers are focusing on distributed IDSs to circumvent the problems of centralized approaches. A major concern of fully distributed IDSs is the high false positive rates of intrusion alarms which undermine the usability of such systems. We believe that effective distributed IDSs can be designed based on principles of coordinated multi-agent systems. We propose an Agent-Based Distributed Intrusion Alert System (ABDIAS) which is fully distributed and provides two capabilities in addition to other functionalities of an IDS: (a) early warning when pre-attack activities are detected, (b) detecting and isolating compromised nodes by trust mechanisms and voting-based peer-level protocols.
机译:在当今的网络社会中,计算机系统的入侵检测是一个关键问题。当前的分布式入侵检测系统(IDS)尚未完全分布,因为它们中的大多数会集中分析从分布式节点收集的数据,从而导致单点故障。研究人员越来越关注分布式IDS,以规避集中式方法的问题。完全分布式IDS的一个主要问题是入侵警报的高误报率,这会破坏此类系统的可用性。我们认为,可以基于协同多主体系统的原理来设计有效的分布式IDS。我们提出了一种基于代理的分布式入侵警报系统(ABDIAS),该系统是完全分布式的,除IDS的其他功能外,还提供两种功能:(a)在检测到攻击前活动时进行预警,(b)检测并隔离受感染的计算机节点通过信任机制和基于投票的对等级别协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号