首页> 外文会议>International Workshop on Cooperative Information Agents >High-Performance Agent System for Intrusion Detection in Backbone Networks
【24h】

High-Performance Agent System for Intrusion Detection in Backbone Networks

机译:骨干网络中的入侵检测高性能代理系统

获取原文

摘要

This paper presents a design of high-performance agent-based intrusion detection system designed for deployment on high-speed network links. To match the speed requirements, wire-speed data acquisition layer is based on hardware-accelerated NetFlow like probe, which provides overview of current network traffic. The data is then processed by detection agents that use heterogenous anomaly detection methods. These methods are correlated by means of trust and reputation models, and the conclusions regarding the maliciousness of individual network flows is presented to the operator via one or more analysis agents, that automatically gather supplementary information about the potentially malicious traffic from remote data sources such as DNS, whois or router configurations. Presented system is designed to help the network operators efficiently identify malicious flows by automating most of the surveillance process.
机译:本文介绍了高性能代理的入侵检测系统设计,用于在高速网络链路上进行部署。为了匹配速度要求,线速数据采集层基于硬件加速的NetFlow等探头,其提供了当前网络流量的概述。然后通过使用异物异常检测方法的检测剂处理数据。这些方法是通过信任和声誉模型相关的,并且关于各个网络流的恶意性的结论通过一个或多个分析代理呈现给运营商,它自动收集关于来自远程数据源的潜在恶意流量的补充信息DNS,WHOIS或路由器配置。呈现的系统旨在帮助网络运营商通过自动化大部分监视过程有效地识别恶意流动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号