本文通过借鉴智能代理(agent)技术,并结合XML 和安全通信技术,提出了一种具有两层代理结构的分布式入侵检测系统模型,并设计实现了原型系统。该模型有多个域组成,域内采用分层结构,域间采用P2P(peer to peer)结构。域内的检测agent 分布在受保护各个主机上执行检测任务,检测结果向本域内的数据中心汇报。协作agent 综合本域内数据中心的报警信息进行分析,产生本地报警,并通过XML向其他域中协作agent 告警。作为冗余成分的协作agent 的存在避免了系统结构上的单点失效。数字签名和加密技术确保了agent 通信的安全。分布性、健壮性、智能性和协作性是该系统模型主要特点。 关键词:协作;Agent;IDS;XML;入侵检测系统 [Abstract]: Using agent’s technology for reference, combining XML & security communication technology, we present a distributed intrusion detection system model of two-layer agent structure; we design and implement a prototype system. The model consists of several domains. In each domain, structure is layered, while between each two domains, structure is peer to peer. Every detect-agent of each domain monitors the host-protected in the network and the result of monitor is reported to data center in the same domain. Cooperative agent synthesizes the result of every detect-agent in the same domain, analyze it and give an alarm to local domain and to the cooperative agent of other domain with XML. Cooperative agent of Redundancy avoids malfunction of single cooperative agent in the model. The digital signature and encrpytion techniques ensure security of correspondence between agents. This system model possesses characteristics such as distribution, robustness,intelligence and cooperation nature etc. [key words]: cooperation; Agent; IDS;XML