首页 | 官方网站   微博 | 高级检索  
     

一种可扩展的高效入侵监测平台技术
引用本文:杨武,方滨兴,云晓春.一种可扩展的高效入侵监测平台技术[J].软件学报,2007,18(9):2271-2282.
作者姓名:杨武  方滨兴  云晓春
作者单位:1. 哈尔滨工程大学,信息安全研究中心,黑龙江,哈尔滨,150001
2. 哈尔滨工业大学,计算机网络与信息安全技术研究中心,黑龙江,哈尔滨,150001
基金项目:国家高技术研究发展计划(863计划);国家242信息安全计划
摘    要:为了在更高带宽的网络中进行有效的入侵检测分析,研究了入侵检测中的数据获取技术,提出了一种可扩展的高效入侵监测框架SEIMA(scalable efficient intrusion monitoring architecture).在SEIMA结构模型中,通过将高效网络流量负载分割器与多个并行工作的入侵检测传感器相结合,从而可以将入侵检测扩展应用到更高的网络带宽中;通过使用高效地址翻译技术和缓冲区管理机制实现了旁路操作系统的高性能用户级网络报文传输模型,以便提高单传感器的报文处理性能;通过采用有限自动机的方法构建了基于用户层的多规则报文过滤器以消除多余数据包的处理开销.模拟环境和实际环境下的测试结果表明,SEIMA在提高网络入侵检测系统数据获取效率的同时,能够降低系统CPU的利用率,从而可以将更多的系统资源用于更复杂的数据分析过程.

关 键 词:入侵检测  负载均衡  数据收集  地址翻译  报文过滤  安全分析
收稿时间:2005-01-24
修稿时间:2005-01-242006-03-31

Techniques of Building a Scalable, Efficient Intrusion Monitoring Architecture
YANG Wu,FANG Bin-Xing and YUN Xiao-Chun.Techniques of Building a Scalable, Efficient Intrusion Monitoring Architecture[J].Journal of Software,2007,18(9):2271-2282.
Authors:YANG Wu  FANG Bin-Xing and YUN Xiao-Chun
Affiliation:1.Information Security Research Center, Harbin Engineering University, Harbin 150001, China;Computer Network and Information Security Technique Research Center, Harbin Institute of Technology, Harbin 150001, China
Abstract:To perform effective intrusion analysis in higher bandwidth network, this paper studies the data collecting techniques and proposes a scalable efficient intrusion monitoring architecture (SEIMA) for network intrusion detection system (NIDS). In the architecture of SEIMA, scaling network intrusion detection to high network speeds can be achieved using multiple sensors operating in parallel coupled with a suitable load balancing traffic splitter. High-performance data transfer is achieved through asynchronous DMA without OS's intervention by using efficient address translation technique and buffer management mechanism. Multi-rule packet filter based on finite state machine technique is implemented at user layer to eliminate overhead for processing redundant packets. The simulative and actual experiment results indicate that SEIMA is capable of reducing the using rate of CPU while improving the efficiency of data collection in NIDS, so as to save much more system resources for complex data analysis in NIDS. The method of SEIMA is very practical for network security.
Keywords:intrusion monitoring  load balance  data collection  address translation  packet filter  security analysis
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号