Design and Implementation of a Distributed Cooperative Intrusion Detection System

段海新,吴建平
DOI: https://doi.org/10.13328/j.cnki.jos.2001.09.015
2001-01-01
Ruan Jian Xue Bao/Journal of Software
Abstract:An integrative taxonomy for intrusion detection technologies is proposed, which can specify accurately existing intrusion detection methods. Aiming at multiple-domain environments, a distributed cooperative intrusion detection system (DCIDS) is designed, which implements cooperative intrusion detection through efficient, secure information exchange among IDSes in different domain. The architecture of intrusion detection systems is described, as well as its four components: sensor, analyzer, manager and user-interface. Some key issues are also discussed, including secure communication and selection of detection places.
What problem does this paper attempt to address?