提出一种主动实时防护模型,每个节点上的监视agent收集其周围邻居节点的行为信息,并向每个区域内的决策agent汇报,决策agent进行判断,发现入侵者后,产生阻击agent在入侵者周围形成一道移动防火墙,将入侵者包围并隔离于网络,消除入侵行为.该模型通过多种功能的移动agent组成一个有机整体来实现主动入侵响应.实验结果表明,本模型能够有效地阻止入侵行为.
The nature of ad hoc networks makes them vulnerable to security attacks. Many security technologies such as intrusion prevention and intrusion detection are passive in response to intrusions in that their countermeasures are only to protect the networks and there is no automated, network-wide counteraction against detected intrusions. This paper proposed an architecture of cooperation intrusion response based multi-agent. The architecture is composed of mobile agents. Monitor agent resides on every node and monitors its neighbor nodes. Decision agent collects information from monitor nodes, and detects an intrusion by security policies. When an intruder is found in the architecture, the block agents will get to the neighbor nodes of the intruder and form a mobile firewall to isolate the intruder. In the end, the model was evaluated by simulation and test bed.