Abstract:
A real time self-adjusting reduction algorithm is provide, which is based on the notion of reduction and distributed processing. The algorithm is implemented in Java. Validity and effectivity of the algorithm has been testified on an experimental platform. As far as is known, in DIDS, reduction effect, real time performance of alert response and system performance cannot be optimal simultaneously. The algorithm is enabled to adjust in reduction effect and the system performance optimized by changing some parameters, and it is thus provided to present a new approach to the design of effective and stable intrusion detection systems.