Font Size: a A A

Research On Layer-based Distributed Intrusion Detection System

Posted on:2009-12-14Degree:MasterType:Thesis
Country:ChinaCandidate:H W LiFull Text:PDF
GTID:2178360242989622Subject:Computer system architecture
Abstract/Summary:PDF Full Text Request
Intrusion Detection System is a network security insurance system that can take action after identifying suspicious behaviors of accessing to networks and hosts. It's a very important means to insure network security. However, how to enhance efficiency of Intrusion Detection System becomes an urgent task just because it gets involved in many complex calculations and large number of monitoring data. Therefore, this paper studies a high-efficiency and layer-based Distributed Intrusion Detection System, taking the architecture of Intrusion Detection System as the entry point.According to its functions, this paper divides Distributed Intrusion Detection System into three layers: data collection layer, data analysis layer and decision-making control layer, aiming to seek for a method to enhance detection efficiency of Intrusion Detection System. The contents of this paper are listed as follows:For data collection layer, the paper analyzes sensor's working principle, security problems and packets capturing technology, and designs its distributed allocation policy. Especially, it applies packet-analysic-based Load-Balance technology of IDS dataflow into this layer, and studies Load-Balance algorithm simultaneously.For data analysis layer, this paper designs the architecture of data analysis module and its distributed allocation policies, and analyzes the data detection process. Besides, an algorithm of String-Matching named BM algorithm is introduced into this layer. In order to resolve problems of tasks allocation, it also puts forward an algorithm named dynamic IDS tasks allocation algorithm based on resources occupation.For decision-making control layer, this paper studies its architecture and functions of each module.This paper also analyzes and designs the communication mechanism and cooperation mechanism of the layer-based Distributed Intrusion Detection System, including the communication between different layers or different modules in the same layer. It also studies the contents and basic models of cooperation.Finally, this paper designs a test platform of the Distributed Intrusion Detection System by using Linux-based Snort software. The configure items of IDS hosts, servers and analyst-control-consoles are listed in detail. Then, a series of simulated attacks are tested on the platform and the results are checked by using ACID tool.Through analyzing the test results, it proves that the system is available and effective.
Keywords/Search Tags:Distributed Intrusion Detection System, Layer, Load-Balance, Task allocation
PDF Full Text Request
Related items