针对现有的分布式入侵检测系统存在检测准确性低、可扩展性差问题,提出一种具有动态可插拔的协同入侵检测模型。该模型主要由检测实体、行为库、协同控制器构成,采用代理技术和Jini技术实现,具有自管理、自修复和跨平台的特性,系统中的各代理可以即插即用,并且能与其它代理进行协同检测。实验结果表明,该模型提高了入侵检测系统的准确性和扩展性。
According to low accuracy and poor scalability exists in present distributed intrusion detection system,the dynamic pluggable coordination intrusion detection model which consisted of detection entity,behavior library and coordination controller is proposed.The model with the properties of self-management,self-healing and cross-platform is implemented by agent and Jini.Each agent is dynamic pluggable and can carry on the coordination detection with other agents.Experimental results show that the model improves the accuracy and scalability of intrusion detection systems.