计算机应用 ›› 2014, Vol. 34 ›› Issue (1): 86-89.DOI: 10.11772/j.issn.1001-9081.2014.01.0086

• 计算机安全 • 上一篇    下一篇

基于人工免疫的分布式入侵检测模型

程建,张明清,刘小虎,范涛   

  1. 信息工程大学 密码工程学院,郑州 450001
  • 收稿日期:2013-07-08 修回日期:2013-09-01 出版日期:2014-01-01 发布日期:2014-02-14
  • 通讯作者: 程建
  • 作者简介:程建(1990-),男,河南安阳人,硕士研究生,CCF会员,主要研究方向:基于人工免疫的入侵检测及其建模仿真;张明清(1961-),男,湖北孝感人,副教授,主要研究方向:系统建模与仿真;刘小虎(1989-),男,河南太康人,硕士研究生,主要研究方向:网络安全建模仿真;范涛(1990-),男,安徽安庆人,硕士研究生,主要研究方向:网络安全信任机制建模仿真。

Distributed intrusion detection model based on artificial immune

CHENG Jian,ZHANG Mingqing,LIU Xiaohu,FAN Tao   

  1. Institute of Cipher Engineering, Information Engineering University, Zhengzhou Henan 450001, China
  • Received:2013-07-08 Revised:2013-09-01 Online:2014-01-01 Published:2014-02-14
  • Contact: CHENG Jian

摘要: 针对现有分布式入侵检测系统交互流量大、单点失效及检测效率偏低的问题,基于人工免疫理论建立了一种新的分布式入侵检测模型,并提出了一种中心检测器配置及使用方法,并将异常检测与误用检测相结合。基于OMNeT+〖KG-*3〗+网络仿真平台设计了仿真模型,进行了仿真实验。仿真实验结果表明,改进模型交互流量明显减小,检测效率明显提高并有效解决了单点失效问题。仿真结果证明了改进模型的正确性与有效性。

关键词: 入侵检测, 分布式, 人工免疫系统, 阴性选择, 分布式拒绝服务攻击

Abstract: Concerning the problem of excessive interaction flow, single point failure and low detection efficiency in existing Distributed Intrusion Detection System (DIDS), a new distributed intrusion detection model based on artificial immune theory was proposed. The new distributed intrusion detection model presented a central detector configuration and method of use and combined misuse detection and anomaly detection. The simulation model was designed based on OMNeT+〖KG-*3〗+ network simulation platform and experiments were run. According to the simulation results, the model overcomes excessive interaction flow problem of the fully distributed system, solves the problem of single point failure and improves the detection efficiency effectively. The simulation results verify the validity and effectiveness of the improved model.

Key words: intrusion detection, distributed, Artificial Immune System (AIS), negative selection, Distributed Denial of Service (DDoS)

中图分类号: