论文提出了层次化协作式IDS的体系结构和适应这种体系结构的扩展的入侵检测消息交换格式(EIDMEF),设计实现了入侵检测控制信息交换格式模块和控制器与控制器间消息交换格式模块。部署方案和性能分析表明层次化协作式IDS部署方便、实用性好,消除了中心控制器引起的瓶颈问题。
A architecture of hierarchical cooperation IDS is presented, the message exchange format of intrusion detection message exchange format is extended to accommodate this architecture. We design a model of intrusion detection control information exchange format and a model of information exchange format between controllers. Disposition scheme and performance analyses indicate the model is easy to disposition and has a good future for application.