在分析现有基于Agent的人侵检测系统的基础上,提出了一种基于Agent的DIDS(Distributed Intrusion Detection System,分布式入侵检测系统)模型,系统采用分布检测,分布处理的模式,通过多Agent技术的思想建立DIDS整体结构,用Agent实现不同的功能单元,给出了模型的各个组成部分,并对模型中各种Agent的功能设计和实现原理进行了分析;尽管Agent的相关理论和系统有待发展与完善,但由于网络系统的分布式的特点以及网络应用的发展,基于Agent的检测框架应是未来IDS发展的重要方向。
A distributed intrusion detection system model based on Agent is brought up by analyzing the existed Agent--based IDS. It builds up a DIDS model by adopting the method of distributed detection, distributed processing and thinking of multi-Agent. It also realizes the different function unit with Agent, describes all the composed parts of DIDS model, and analyzes the function design and implement principle in Agent. Though the theories and systems associated with Agent wait to be improved, in the future, the development of IDS will focus on an Agent-based detection framework because of distributed characteristic of network and developing network applications.