欢迎访问中国科学院大学学报,今天是

中国科学院大学学报 ›› 2005, Vol. 22 ›› Issue (2): 202-209.DOI: 10.7523/j.issn.2095-6134.2005.2.013

• 论文 • 上一篇    下一篇

分布式入侵检测系统的协作交互研究

连一峰   

  1. 信息安全国家重点实验室(中国科学院研究生院) 北京 100049;
  • 收稿日期:2004-05-11 发布日期:2005-03-15
  • 通讯作者: 连一峰,E-mail:lianyf@vip.sina.com
  • 基金资助:

    国家自然科学基金重点项目(90104030);国家973项目(G1999035801)资助

A Study on Information Exchange and Cooperation in Distributed Intrusion Detection Systems

LIAN Yi-Feng   

  1. State Key Laboratory of Information Security(Graduate School of the Chinese Ac ademy of Sciences), Beijing 100049, China
  • Received:2004-05-11 Published:2005-03-15

摘要:

组件之间的信息交互及协作分析是分布式入侵检测系统的关键问题,在基于层次化协作模型分布式入侵检测系统的基础上,分析了检测组件的信息交互需求,从静态分析的角度提出了扩展入侵检测消息交互格式,针对不同类型攻击行为的组件交互及协作流程,进行了动态的流程分析,为检测系统实现高效的入侵事件通报、审计数据收集、入侵事件协作检测和入侵行为分布式响应提供了标准的表述格式和流程定义.

关键词: 分布式入侵检测, 扩展入侵检测消息交互格式, 层次化协作模型

Abstract:

Information exchange and cooperation between components acts as the key problem of distributed intrusion detection system.According to DIDS based on Hierarchical Cooperation Model (HCM), we analyze the requirements of information exchange between detection components in this model.We present the Extended Intrusion Detection Message Exchange Format (EIDMEF)to provide a standard description format which contributes to efficient information exchange and cooperation, such as reporting intrusion incidents, collecting audit data,performing cooperative detection and activating distributed responses to intrusive behaviors.Workflows of information exchange and processing procedure in this model when confronted with different kinds of intrusions are also depicted in detail.

Key words: Distributed Intrusion Detection, Extended Intrusion DetectionMessage Exchange Format , Hierarchical Cooperation Model

中图分类号: