摘要
为将不同类型的入侵检测器组织起来,协同检测不同类型的入侵,提出了基于模糊Petri网的协同入侵检测方法。采用基于负载信息的模糊Petri网推理算法,区分不同类型的入侵并选择相应的入侵检测器,同时使多个入侵检测器承担的检测任务相对均匀。设计了基于模糊Petri网的协同入侵检测系统,通过多个入侵检测器联合检测多种入侵组成的复合入侵,又可以检测不同类型的单个入侵。仿真结果表明,所有的复合入侵能够被多个检测器协同地检测,且92%的入侵数据能够迁移到合适的检测器上。
To organize several different intrusion detectors to detect different kinds of intrusion, the synergetic intrusion detection system based on fuzzy Petri is proposed. The algorithm of fuzzy Petri net is based on information of workloads. It can send the intrusion data to appropriate intrusion detectors according to intrusion types, and make the workloads of these detectors average. The algorithm can detect both different multi-step attacks and different single attacks. System simulation result shows that all of the muhi-step attacks can be detected cooperatively by several detectors and 92% of the intrusion data can be sent to the right intrusion detectors.
出处
《南京理工大学学报》
EI
CAS
CSCD
北大核心
2008年第6期738-742,753,共6页
Journal of Nanjing University of Science and Technology
基金
江苏省自然科学基金(bk2004421)