计算机应用 ›› 2005, Vol. 25 ›› Issue (07): 1554-1557.DOI: 10.3724/SP.J.1087.2005.01554

• 信息安全 • 上一篇    下一篇

基于本体的协同式入侵检测系统

陈刚1,陈伟2   

  1. 1.中国联通有限公司 广州分公司,广东 广州 510655; 2.武汉大学 计算机学院,湖北 武汉 430072
  • 收稿日期:2005-01-04 修回日期:2005-03-24 发布日期:2005-07-01 出版日期:2005-07-01
  • 作者简介:陈刚(1979-),男,湖北黄冈人,硕士,主要研究方向:网络通信、网络安全;陈伟(1979-),男,江苏淮阴人,博士研究生,主要研究方向:软件工程、数据挖掘

Ontology based cooperative intrusion detection system

CHEN Gang1, CHEN Wei2   

  1. 1. Guangzhou Branch, China Unicom; 2.Computer School, Wuhan University
  • Received:2005-01-04 Revised:2005-03-24 Online:2005-07-01 Published:2005-07-01

摘要:

经过对现有的入侵检测系统的分析,认为多点协同检测能够使入侵检测系统更加准确、有效地检测入侵。提出一种基于本体的模式匹配方法,同时对协同式入侵检测的体系结构与协调方法进行了讨论,它可以使检测工作更加灵活,另外也提供了全局的信息定位以支持协同检测。

关键词: 入侵检测, 本体, 协同检测协同检测

Abstract:

After a survey of present IDSs, it was concluded that more accurate and efficient detection result could be obtained by using multi-sensor cooperative detection. A matchmaking method based on ontology was given to improve flexibility of detection. Cooperative detection framework based on the ontology was also discussed.

Key words: intrusion detection, ontology, cooperative detection

中图分类号: