通过对现有多代理技术的分布式入侵检测系统的研究,提出了一种基于多代理技 术可自检的分布式入侵检测系统模型,并且对该模型的结构,组成和代理的处理流程进行了描述,该模型是一个开放的系统模型,具有很好的可扩展性,易于加入新的入侵检测代理及相应的自检,也易于增加新的入侵检测模式,代理之间的协同采用代理守护进程来实现。 关键词:入侵检测;代理/多代理;系统自身安全 Intrusion Detection System Based Distributed Model With Multi-agent Technique of Detection Owner Lv Jia-xiang , Li Yi-fa (Institute of Information Engineering, Information Engineering University, ZhengZhou 450002, China) Abstract: By dealing with the current intrusion detection system (IDS) with multi-agent technique. a based distributed system model with multi-agent technique of detection owner in presented, and its architecture, components and intrusion agent(IDS)processing flow chart are described in this paper, as well. This model is extended, as an open system, to which the new IDAs detection owner and ID modes can be easily added. Communications of these agents are realized by DEMON threads. Key words: intrusion detection;agent/multi-agent;system security