Abstract:Aiming at the defect of centralized data processing in the current IDA system, the accuracy of system intrusion detection is affected. The design of distributed intrusion detection system based on Agent artificial intelligence technology is proposed. With the support of the overall structure of the system, the analysis control center, network host, partition control center and Agent library are analyzed. According to the response rules in the response library, the corresponding response strategy is adopted, and the communication module is used to timely determine whether the intrusion behavior is abnormal. The S5720S-28P-SI-AC 24-port full Gigabit Layer 3 network management enterprise-level network core switch is used for data exchange. Select AD2032 type alarm responder to be able to monitor the behavior of foreign intrusion. Through V1.2 green computer information detector, comprehensive evaluation of system memory and drive disk. Analyze the implementation method, communication message format and communication protocol of the subject, and design the data movement process based on Agent. With the help of Libpcap library function, design the intrusion detection process. Set the attack environment and parameters. According to the system debugging results, the highest detection accuracy of the system can reach 99%, and equipment support is provided to ensure the safe use of the network.