摘要
入侵防御系统是最近网络安全技术领域一个重要研究方向。文章针对目前入侵检测系统是以被动方式工作这一弊端,分别引入了分布处理、自治代理以及陷阱技术等主动防御思想,提出了一个基于智能代理的分布式主动入侵防御系统,并给出了该系统的详细设计结构、试验平台以及数据分析。实验结果表明该系统具有实时、可伸缩、主动等优点,能有效发现并阻止多种入侵行为,可以解决传统入侵检测系统长期以来存在的问题。
Nowadays Intrusion Prevention System(IPS) is an important research field in network security technology. Traditional Intrusion Detection System(IDS) usually function passively,cannot protect the system on time.In order to solve this drawback,the architecture of an active intrusion prevention system based on intelligent system has been constructed,combining the various active defense approaches,such as distributed processing,autonomous agent and deception technology and so on.Furthermore,the detailed design architecture,experimentation environment and data analysis are presented.The results show that the system possesses the desirable characteristics of real-time,scalability, active performance and so on,which can detect and prevent intrusion behaviors efficiently,and overcome the critical problems of the traditional IDS.
出处
《计算机工程与应用》
CSCD
北大核心
2005年第31期116-118,188,共4页
Computer Engineering and Applications
基金
黑龙江省自然科学基金"智能网络安全系统研究"(编号:F2005-06)支持
关键词
入侵防御系统
网络攻击
网络安全
诱捕系统
智能代理
Intrusion Prevention System ,network attack ,network security ,network deception system ,Intelligent Agent