提出了一个基于网络多层次人工免疫系统的入侵检测实时响应模型.此模型包括3个层次的免疫机制:1)基于操作系统(LINUX)内核的免疫机制;2)基于主机的用户访问免疫机制;3)基于自治代理的分布式网络免疫机制.此模型不仅可实时检测及响应各个层次的入侵攻击,而且可利用分布式环境下自治代理间的协同工作,可对攻击源反向追踪及准确定位;还可制定全局安全策略动态调整各个免疫组件的检测阀值,使之具有良好的自适应性、一定的智能性及容错性.
The model of real time response and reverse tracing network multilayer immune system is brought forward .This model involves three immune layers: 1)detecting based on operating system core, 2)detecting based on host users,3)coordinated operation based on distributed network immune agent .It not only real-timely responds to invasion but also reversely traces intrusion source .Being dynamicly adjusted to each immune agent's detecting valve ,the system hase good adaptablity certain degree intelligence and error-tolerating ablity.