论文部分内容阅读
“软件人”(SoftMan,SM)是在Agent、智能机器人、人工生命等技术基础上提出的一个新概念,它为解决当前网络入侵检测系统中存在的诸多问题提供了新的思路。在深入研究入侵检测技术、人工智能和“软件人”先进理论的基础上,提出了一种基于群体“软件人”(Multi-SoftMan,MSM)的智能入侵防御协作模型。模型采取无控制中心的分布式群体“软件人”体系结构,避免了单个中心分析器带来的单点失效问题。每个数据采集部件、检测部件和分析部件都是独立的单元,不仅实现了数据采集的分布化,而且将入侵检测和实时响应分布化,提高了系统的健壮性,真正实现了分布式检测的思想,这有助于解决目前入侵检测系统普遍存在的智能化程度不高、系统不易维护、检测效率低下等问题。
SoftMan (SM) is a new concept based on Agent, intelligent robot, artificial life and other technologies, which provides a new idea for solving many problems existing in network intrusion detection system. Based on in-depth research on the advanced technologies of intrusion detection, artificial intelligence and software, this paper proposes an intelligent intrusion prevention collaborative model based on community “Multi-SoftMan ” (MSM). The model takes a distributed group “software man ” architecture without a control center and avoids the single point of failure caused by a single central analyzer. Each data acquisition component, detection component and analysis component are independent units, which not only realize the distribution of data acquisition, but also distribute the intrusion detection and real-time response, improve the robustness of the system and truly realize the distributed detection Thinking, which helps to solve the current prevalence of intrusion detection system, the degree of intelligence is not high, the system is not easy to maintain, detection inefficiency and other issues.