YP绍了入侵检测及入侵响应系统中的自适应技术。提出了基于代理的自适应分层入侵检测系统(AAHIDS,Agent—based Adaptive Hierarchical Intrusion Detection System)和基于代理的自适应入侵响应系统(AJRS,Agent—based Adaptive Intrusion Response System)。它们通过调整负责检测入侵行为的系统资源来实现自适应性,动态调用新的底层检测代理的组合以及调整与这些底层代理相关的置信度来适应变化的环境。通过增加过去已获得成功的响应机制的权值,使成功的响应机制获得更多的调用机会来实现响应的自适应性。
It introduces adaptation in intrusion detection and intrusion response. An agent- based adaptive hierarchical intrusion detection system (AAHIDS) and agent- based adaptive intrusion response system (AAIRS) are brought forth. They adjust the system resource used to detect intrusion action to realize adaptation, adapt to the variant circumstance by invoking new combination of low level detection agent dynamic and adjusting the confidence metric of these low level agent. Finally they increase the weight of the successful response, which make the response get more chance to be called to realize the adaptation of the response system.