论文部分内容阅读
入侵检测技术是继“防火墙”、“数据加密”等传统安全保护措施之后新一代的安全保障技术。它对计算机和网络资源上的恶意使用行为进行识别和响应 ,不仅检测来自外部的入侵行为 ,也监督内部用户的未授权活动。提出一种基于部件的入侵检测系统 ,具有良好的分布性和可扩展性。它将基于网络和基于主机的入侵检测系统有机地结合在一起 ,提供集成化的检测、报告和响应功能。在网络引擎的实现上 ,使用了协议分析和模式匹配相结合的方法 ,有效地减少了目标的匹配范围 ,同时改进了匹配算法 ,使网络引擎具有更好的实时性能。
Intrusion detection technology is the next generation of security technologies following the traditional security measures such as “firewall” and “data encryption.” It identifies and responds to malicious use of computers and network resources by not only detecting intrusion from outside but also monitoring unauthorized activity of internal users. A component-based intrusion detection system is proposed with good distribution and scalability. It combines web-based and host-based intrusion detection systems organically to provide integrated detection, reporting and response capabilities. In the implementation of network engine, a method combining protocol analysis and pattern matching is used, which effectively reduces the matching range of the target and improves the matching algorithm so that the network engine has better real-time performance.