介绍了现有入侵检测系统在计算机以及网络安全中的意义和现有入侵检测系统的局限性,简述了移动代理和P2P技术的优点,提出了一种采用移动代理技术和P2P结构的入侵检测系统,避免了当前分布式入侵检测系统存在的单点失效和传输瓶颈问题,提高了系统的自身安全性和各结点的协同检测能力。该系统能够根据环境的变化来进行调整,具有较强的可伸缩性。重点介绍了该系统的结构以及判断入侵的方法。
Introduces the role of intrusion detection systems in computers and network security and the limits of present intrusion detection systems, outlines the advantages of mobile agents and P2P technology. A novel intrusion detection system based on P2P architecture and mobile agent technology is proposed in this paper, It can avoid the questions of the simplepoint invalidation and the transmission bottleneck in the current distributed intrusion detection systems, and enhance the security and collaborative detection capability of the model. The model is scalable and can adjust itself dynamically to adapt to the environmental change. Introduced with emphasis this kind of system structure as well as the judgment invasion method.