针对当前入侵检测系统的大量数据快速匹配要求和对攻击类型的适应性问题,设计并实现了采用计数布隆过滤器(CBF)技术的分布式入侵检测系统。介绍了CBF的原理,对基于CBF技术的模式匹配引擎设计方法和整个系统的实现原理进行了说明。采用CBF实现了快速匹配,动态修改CBF的参数和匹配规则,以快速适应新的攻击类型。实验结果表明,该系统性能和适应性得到显著提升。
To dissolve the present deficiencies of fast matching for massive data and adaptability of attack type in intrusion detec-tion system,a distributed intrusion detection systems based on counting bloom filter (CBF)was designed and implemented.Af-ter a brief introduction of the principle of CBF,the design method of the matching engine based on CBF technology and mecha-nism of the whole system were explained.The system leveraged CBF to carry out fast matching,and could modify the parame-ters and matching rules of CBF to suit new attack types quickly.The results of the experiment showed that its performance and adaptability had been improved greatly.