期刊文献+

基于网络的入侵检测系统的感应器组件 被引量:2

A Sensor Component for Network-Based Intrusion Detection System
下载PDF
导出
摘要 从简化入侵检测系统的构造出发 ,设计和实现了一个基于网络的入侵检测系统的感应器组件 .该组件提供了较为全面的功能 ,包括采集网络数据、IP重组、TCP层重组和基于多种应用层协议的数据还原 .该组件具有灵活的模块化结构 ,提供了很好的复用性和扩展性 ,并实现了自定义加载的功能 .用户可以根据实际需求定制组件的大小 ,或者添加自定义的模块到组件中 . To simplify the construction of an intrusion detection system, a sensor component for network-based intrusion detection system is designed and implemented. This component can be used to grasp data packet from network, to reconstruct the IP packet, to reestablish the TCP layer data flow and to restore data of application layer. Based on the module designing method, the component is highly reusable and expandable. With the support of 'loading according to configuration' mechanism, users can readily add to or remove a module from this component. This mechanism enables users to customize the component on the demand of specified requirements so as to make the system more efficient.
出处 《北京理工大学学报》 EI CAS CSCD 北大核心 2002年第5期615-617,625,共4页 Transactions of Beijing Institute of Technology
关键词 组件 入侵检测系统 感应器 数据采集 IP重组 TCP层重组 网络安全 intrusion detection system sensor data gathering IP assembling
  • 相关文献

参考文献5

  • 1[1]Amoroso E G. Intrusiom detection: An introduction to internet surveillance, correlation, traps, trace back, and response[M]. Sparta, NJ: Net Books,1999.
  • 2[2]Allen J, Christie A, Fithen W, et al. State of the practice of intrusion detection technologies[R]. Technical Report CMU/SEI-99-TR-028,2000.
  • 3[3]Vigna G, Kemmerer R A. Net STAT: A network-based intrusion detection system[J]. Journal of Computer Security, 1999,7(1):37-50.
  • 4[4]Mark R, Stillman M. Open infrastructure for scalable intrusion detection[Z]. IEEE Information Technology Conference, Syracuse, NY, 1998.
  • 5[5]Wrigth G, Stevens R. TCP/IP Illustrated, Volume 2[M]. Baltimore, MD: Addison-Wesley Publishing Company, 1995.

同被引文献2

引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部