...
首页> 外文期刊>Journal of Parallel and Distributed Computing >Detection workload in a dynamic grid-based intrusion detection environment
【24h】

Detection workload in a dynamic grid-based intrusion detection environment

机译:动态的基于网格的入侵检测环境中的检测工作量

获取原文
获取原文并翻译 | 示例

摘要

Denial-of-service (DoS) and distributed denial-of-service (DDoS) are two of the most serious and destructive network threats on the Internet. Hackers, exploiting all kinds of malicious packages to attack and usurp network hosts, servers and bandwidth, have seriously damaged enterprise, campus and government network systems. Many network administrators employ intrusion detection systems (IDSs) and/or firewalls to protect their systems. However, some systems lose most of their detection and/or protection capabilities when encountering a huge volume of attack packets. In addition, some detection resources may fail due to hardware and/or software faults.In this paper, we propose a Grid-based platform, named the dynamic grid-based intrusion detection environment (DGIDE), which exploits Grid's abundant computing resources to detect a massive amount of intrusion packets and to manage a dynamic environment. A detector, a node that detects attacks, can dynamically join or leave the DGIDE. A newly joined detector is tested so that we can obtain its key performance curves, which are used to balance detection workload among detectors. The DGIDE backs up network packets. When, for some reason, a detector cannot continue its detection thus leaving an unfinished detection task, the DGIDE allocates another available detector to take over. Therefore, the drawbacks of ordinary security systems as mentioned above can be avoided.
机译:拒绝服务(DoS)和分布式拒绝服务(DDoS)是Internet上最严重的两种破坏性网络威胁。黑客利用各种恶意软件包攻击和篡改网络主机,服务器和带宽,严重破坏了企业,校园和政府网络系统。许多网络管理员采用入侵检测系统(IDS)和/或防火墙来保护其系统。但是,某些系统在遇到大量攻击包时会失去大部分检测和/或保护功能。此外,某些检测资源可能会由于硬件和/或软件故障而失败。本文提出了一种基于网格的平台,称为动态基于网格的入侵检测环境(DGIDE),该平台可利用Grid丰富的计算资源进行检测。大量入侵数据包并管理动态环境。检测器(检测攻击的节点)可以动态加入或离开DGIDE。对新加入的检测器进行了测试,以便我们获得其关键性能曲线,这些曲线可用于平衡检测器之间的检测工作量。 DGIDE备份网络数据包。当由于某种原因检测器无法继续其检测从而导致未完成的检测任务时,DGIDE会分配另一个可用的检测器来接管。因此,可以避免上述普通安全系统的缺点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号