Dissertation > Excellent graduate degree dissertation topics show
Research on Parallel and Distributed Intrusion Detection Technologies
Author: WangZuo
Tutor: YinJianPing
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Intrusion Detection Parallel detection Distribution detector Traffic into Load balancing Divergence
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 17
Quote: 0
Read: Download Dissertation
Abstract
|
Intrusion detection technology is an important technical means to ensure network security. But as network traffic and bandwidth grows exponentially, the traditional single-point detection has been difficult to meet the demand of the network environment, the performance of intrusion detection system, based on the flow rate by parallel detection technology as an effective solution, is becoming a hot topic ; based on the detected traffic information on a single link, it is difficult to effectively detect scan, DDoS distribution of multi-connection attack is therefore necessary to use a plurality of detectors in the network to carry out the distribution detection. But no matter for intrusion detection in parallel or distributed intrusion detection, the existing solution exists various deficiencies. To this end, this paper Parallel and Distributed intrusion detection technology. Mainly include unified parallel detection architecture, different strategies to keep evidence and load balancing of the traffic division algorithm, design a probe-based real-time processing speed of the traffic division algorithm; efficient distributed detection mechanisms, the development of a comprehensive Parallel and distributed detection system performance evaluation platform. The contribution of this article and innovations are as follows: (1) Consolidated been parallel detection characteristics of the architecture, parallel detection of a unified architecture UPDA (at Uniformed Parallel Detection Architecture). UPDA contain the functionality required by the parallel detection module, wherein the distribution module, mapping the forwarding module and the detection analysis module is a basic module, the communication management module, the coordination module is the main function modules. The UPDA able as the realization of research and testing platform. (2) summarize and analyze the evidence to maintain and load balancing algorithm for the traffic division, the basic strategy. The traffic partitioning algorithm is one of the core parallel detection system. The two basic requirements: to keep the detection of evidence required for all attacks and keep the load balanced. Analyzed most of the traffic division of the algorithm, the basic strategy that will achieve the evidence to remain divided into divided based attack scenario, based on Hash map to achieve load balancing strategy based on correlation between flows, on Sensor communication and other four strategies; divided Static strategy and dynamic strategy, in which the dynamic policy is divided into the activation policy and proactive strategy of two categories. Keep the evidence summary and analysis of the strategy and basic load balancing can guide the design of the traffic division algorithm. (3) design based on real-time processing of the detector speed the flow the division algorithm RTPSF (, Real-Time Processing Speed ??Feedback). RTPSF load information according to the feedback, the dynamic partitioning of the network traffic, superior in load balancing traditional cyclically algorithm. RTPSF real-time processing speed of the detector to characterize the load, the size of the network traffic beyond the parallel processing power of the detection system, the algorithm is able to detect and alarm. Workflow by analyzing a single intrusion detection system, a method to calculate the instantaneous processing speed, and puts forward a mathematical formula to assess the real-time processing speed based on the instantaneous processing speed. (4) The proposed the efficient distribution detecting mechanism EDDS (Efficient Distributed Detection Scheme). EDDS can be false negative / false positive rate is limited to a certain limit within the premise of the detector in the divergence of the measurement through the source of the improved dynamic bit sharing technology, effectively reducing the storage overhead; coordination in the detector and the center between the communication algorithm based on random probability, including both static and adaptive strategies to effectively reduce communication overhead. Mathematical analysis, the minimum guaranteed performance targets random communication probability P. (5) the development of a comprehensive performance evaluation of parallel and distributed detection system platform. The platform module by a different combination of features, either parallel intrusion detection system performance assessment can also evaluate the performance of distributed intrusion detection system. Performance evaluation platform is the basis of this paper to carry out the verification of the algorithm performance analysis. Around the performance evaluation platform, also developed a peripheral data processing and analysis tools, including the optimal input parameters selection tools, network traffic distribution statistical tools, analysis tools of experimental results.
|
Related Dissertations
- Research on Parallel Frequent Graph Pattern Mining,TP311.13
- Research on the Traffic Problem of Historic Block in the City,TU984.191
- Research on Peer-to-Peer Traffic Identification Algorithm Based on Cluster Analysis,TP393.02
- The Space Development Pattern Research on Since Motorists Camp of Fujian Province,G895
- Intrusion detection based on the ultrasonic echo envelope in the military security patrols,E919
- Based on Rough Set of Urban Areas When Traffic Green Control System Research,TP18
- The Study about the Correlation between the Information on Traffic Violations and the Rate of Compul-sory Insurance in ZheJiang,D631.5
- Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
- Moving target trajectory analysis based Intelligent Traffic Monitoring System,TP277
- Road Traffic Safety Comprehensive Evaluation Method,U492.8
- Remote sensing data processing grid platform design and initial implementation,TP79
- Intelligent video detection technology based on the traffic lights control,TM923.5
- Enforcement of Traffic Police,D631.5
- Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
- On the Crime and the boundaries of the crime of endangering public safety by dangerous means,D924.3
- Research on the Feasibility of Highway Construction Project,F542
- Research on Micro Simulation of Urban Road Guide Signs and It’s Realization,U491.52
- An Analysis on the Countermeasures for Easing the Traffic Problems in Nanchang City,U491
- Analysis of traffic crime problems,D924.3
- The Research on Intrusion Detection System Based on Machine Learning,TP393.08
- The Research on Regulation of Criminal Law on Dangerous Driving and Some Comments on Article 22 of Amendment Viii to the Criminal Law,D924.3
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|