论文部分内容阅读
通过充分利用入侵检测各类产品的安全防护特点,本文设计了一种策略分流的入侵防御及恢复系统架构.采用双NIDS系统作为前端检测模块,通过策略分流,使得双NIDS系统全面覆盖入侵检测的各个协议层,充分发挥两种NIDS系统的检测优势,实现高效的入侵检测.并结合HIDS的主机日志防护机制及关键内容恢复机制,在即便出现入侵破坏数据的情况下,仍可保证系统的关键部位安全.
By taking full advantage of the security features of intrusion detection products, this paper designs a policy-diverting intrusion prevention and recovery system architecture.Using dual NIDS system as the front-end detection module, through the strategy diversion, the dual NIDS system fully covers the intrusion detection Each protocol layer, give full play to the detection advantages of the two NIDS systems, and achieve efficient intrusion detection.And combined with HIDS host log protection mechanism and key content recovery mechanism, even in the event of invasion and destruction of data, the system can still guarantee the key Site safety.