首页> 外国专利> Intelligent Intrusion Detection System based on distributed intrusion detecting agents

Intelligent Intrusion Detection System based on distributed intrusion detecting agents

机译:基于分布式入侵检测代理的智能入侵检测系统

摘要

The present invention relates to an intelligent intrusion detection system based on a distributed intrusion detection agent, the delivery of the dynamic collection with information from the intrusion detection agent distributed learning and detection agents study detected character code to the detector.; An object of the present invention is to increase the intrusion detection rate of the total dispersion agent.; The present invention is detected by the IDS engine chair plurality of detection to obtain a kernel audit data provided by the system in accordance with the code identifying the suspected degree through which characters; Coordinator of the detector to automatically receive the intrusion action to take appropriate measures to inform the current intrusion alert to determine whether the intrusion of computer nodes or intrusion intrusion doubts about being passed from the detection of each party; Normal state, and by collecting the information of the abnormality intrusion steady state operation and the unsteady state operation scenario generator for virtually generating a work order; It includes the detector learning machine for distributing the detected character code learning by learning characters detected through the scenario generated by the scenario generator.; Since, according to the present invention to study the penetration pattern for detecting the agent with this by dynamically collecting the intrusion information hackers from each of the detection agent distributed on the basis of the variance detection agent distribution the learned detected character code entire dispersion agent the intrusion detection rate can be improved.
机译:基于分布式入侵检测代理的智能入侵检测系统技术领域本发明涉及一种基于分布式入侵检测代理的智能入侵检测系统,该动态收集的信息来自入侵检测代理,分布式学习和检测代理将检测到的字符代码研究到检测器中。本发明的目的是提高总分散剂的侵入检测率。通过IDS引擎椅子对本发明进行多次检测,以获取系统提供的核查数据,并根据该代码确定可疑程度,通过该字符识别字符;检测器的协调器自动接收入侵行为,以采取适当措施通知当前的入侵警报,以确定是否对计算机节点的入侵或入侵入侵是否怀疑是从各方的检测中传递出来的;正常状态,并通过收集异常入侵稳态操作和非稳态操作场景产生器的信息,虚拟地产生工作指令;它包括检测器学习机,该检测器学习机用于通过学习通过情境产生器生成的情境检测到的角色来分发检测到的角色代码学习。由于根据本发明,通过从基于方差检测代理分布而分配的每个检测代理中动态地收集入侵信息黑客来学习用于检测代理的渗透模式,因此学习的检测字符代码整体分散代理,可以提高入侵检测率。

著录项

  • 公开/公告号KR100332891B1

    专利类型

  • 公开/公告日2002-04-17

    原文格式PDF

  • 申请/专利权人 이종성;

    申请/专利号KR19990011938

  • 发明设计人 이종성;

    申请日1999-04-07

  • 分类号G06F15/00;

  • 国家 KR

  • 入库时间 2022-08-22 00:29:49

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号