论文部分内容阅读
网络入侵检测系统主要是对入侵行为的检测识别。它通过安装入侵检测引擎,监视网络上的流量,捕获所有网络传输,把这些信息读入内存,由系统与已知的一些典型攻击性分组比较,从中有效的识别出所有网络活动中的已知攻击或可疑的网络行为,发现是否有违反安全策略的行为和被攻击的迹象。
Network intrusion detection system is mainly for detection of intrusion detection. It installs the intrusion detection engine, monitors the traffic on the network, captures all the network transmission, reads this information into the memory, compares the system with known some typical aggressively the grouping, from the effective recognition in all network activities known Attacks or suspicious network activity to find out if there is a violation of security policies and signs of being attacked.