论文部分内容阅读
近年来,随着网络安全问题日益突出,入侵检测也越来越受到关注。目前,研究入侵检测的课题很多,侧重点也各不相同。该文介绍的DIDAPPER系统是一种具有认知能力的分布式入侵检测系统。分布式结构、认知能力和知识的共享是DIDAPPER系统的重要特点。流量标本和IP陷阱是DIDAPPER系统所提出的新概念。DIDAPPER的分布式三级结构使得它适合于检测大规模网络自动攻击行为,而且有较强的可扩展性和高效性。
In recent years, as network security becomes more and more prominent, intrusion detection is getting more and more attention. At present, there are many research topics for intrusion detection, and the emphasis is different. This article describes the DIDAPPER system is a cognitive distributed intrusion detection system. Distributed structure, cognitive ability and knowledge sharing are important features of DIDAPPER system. Flow samples and IP traps are new concepts proposed by the DIDAPPER system. DIDAPPER distributed three-level structure makes it suitable for detecting large-scale network auto-attack behavior, but also has strong scalability and high efficiency.