摘要
在网络环境下入侵行为开始之前需要获取目标的必要信息,为入侵活动做准备,这就是网络中的早期异常活动。介绍的入侵检测系统是基于Agent技术,具有层次化、模块化的结构,在网络中易于部署,不仅可以检测基于知识的入侵,还可以检测基于行为的入侵,能够对早期的异常活动进行有效的报警和记录。
Intrusion behaviour needs necessary information about the target to be ready for the intrusion activities under network environment before it starts, which are early abnormal activities. It is introduced that a new intrusion detection system is based on agent technology, and it is easily deployed into network because of hierarchical and modular structure. The system can detect intrusions based on misuse and has ability to detect abnormal intrusions, and it can effectively find out early abnormal activities in the network and record the intrusion and alarm.
出处
《计算机工程与设计》
CSCD
2004年第11期2067-2069,共3页
Computer Engineering and Design