A novel network security cooperative defense technology is studied and a cooperative control framework based on agent mechanism is proposed to solve the lack of cooperative control and whole effect in traditional defense systems. The technology supports both IPv4 and IPv6 protocols and security modules in the framework are associated with each other to accomplish communication and work together. Furthermore
a network security cooperative defense system is composed and the key functions that support the early-alert
audit
accident recovery
network camouflage and so on are also achieved. The pivotal research is emphasized on the key technologies of system call sequences audit model based on machine learning and cooperative accident recovery. Under the condition of 100 M Data flow speed
the NSCDS software's false negative is less than 6% and its false positive is less than 8%. Besides
all module functions work normally and the system can be used to carry out cooperative defense capability.
关键词
Keywords
references
CNCERT/CC. 2006 annual report by CNCERT [EB/OL]. [2007-10-10]. http:∥www.cert.org.cn, 2007.
BERK V H, GRAY R S, BAKOS G. Using sensor networks and data fusion for early detection of active worms [C]∥Proceedings of the SPIE AeroSense: Sensors, and Command, Control, Communications, and Intelligence Technologies for Homeland Defense and Law Enforcement II. Orlando,FL, USA: SPIE, 2003: 92-104.
FU Chong, WANG Juan, QIN Zhiguang,et al. Macro network security warning and emergency response system [J]. Journal of University of Electronic Science and Technology of China, 2006, 35(4): 702-705.
HU Huaping, ZHANG Yi, CHEN Haitao. The study of large scale networks intrusion detection and warning system [J]. Journal of National University of Defense Technology, 2003,25(1):21-25.
BALEPIN I, MALTSEV S, ROWE J, et al. Using specification-based intrusion detection for automated response[C]∥Proceeding of the 6th International Symposium on Recent Advances in Intrusion Detection. Berlin, Germany: Springer, 2003: 136-154.
LEI Hao, HUANG Jian, FENG Dengguo. A fine-grained coalition access control policy for jointly-owned resources in collaborative environments [J]. Journal of Software, 2005, 16(5): 1000-1011.
HIRAISHI H, MIZOGUCHI F. Design of a visual browser for network intrusion detection[C]∥10th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises. Piscataway, NJ, USA: IEEE, 2001: 132-137.