单家凌.基于Linux的入侵检测系统协同性研究与设计[J].测控技术,2012,31(06):111-114 |
基于Linux的入侵检测系统协同性研究与设计 |
Research and Design of the Cooperativity for an Intrusion Detection System Based on Linux |
|
DOI: |
中文关键词: 蜜罐 主机入侵检测系统 协同性 H-HIDS |
英文关键词:honeypot HIDS(host-based intrusion detection system) cooperativity H-HIDS |
基金项目: |
|
摘要点击次数: 1041 |
全文下载次数: 227 |
中文摘要: |
针对主机入侵检测系统(HIDS)的缺点,提出了一种以日志数据库为连接枢纽的新型防御结构模型(H HIDS)。该结构模型中,蜜罐为HIDS提供补充性的日志数据,入侵行为重定向将HIDS检测到的可疑数据流导向蜜罐,目的是充分利用它们各自的优点,互相分工,协同工作,发挥出它们各自最大的优势,以达到保护特定主机系统最大安全性。通过实验,H-HIDS在报警率和误报率方面具有一定的优越性。 |
英文摘要: |
For disadvantages of the host-based intrusion detection system(HIDS),a log database for connecting the hub to the new defensive structure model is proposed.In the structural model,honeypot provides complementary log data for the HIDS,intrusion redirects the suspicious data flow detected by HIDS to the honeypot,which is to fulfill their respective advantages,each division,working together to play their respective advantages,in order to achieve maximum security for the protection of a particular host system.Through experiment,the H-HIDS has certain superiority in alarm rate and false alarm rate. |
查看全文 查看/发表评论 下载PDF阅读器 |
关闭 |