摘要
由于TCP/IP协议是一个开放的协议,因此网络极易受到攻击。为了能够有效地检测到入侵行为,提出了一种基于部件的分布式入侵检测系统,并结合网管软件系统的开发,在Linux环境下进行了实现。系统主要由控制台、分析系统、存储系统、响应系统、网络引擎和主机代理构成。通过协同工作并采用改进了的Boyer-Moore算法,检测网络入侵行为,有效地维护了信息网络的安全。
Because of the open structure of TCP / IP, the network is vulnerable to attack. In order to availably detect the intrusion, an intrusion detection system based on components is presented, and the implementation of it in Linux environment is made in combination with the development of NMS software. The system consists of manager console, analyzer, storage system, response system, network engine and host agent. By operating cooperatively and using the improved Boyer-Moore algorithm, the network intruding acts can be detected effectively and the information network security is defended.
出处
《空军工程大学学报(自然科学版)》
CSCD
2004年第5期85-88,共4页
Journal of Air Force Engineering University(Natural Science Edition)
基金
国家高技术发展计划(863)基金资助项目(2002A143020)
关键词
入侵检测
网络引擎
网络安全
intrusion detection
network engine
network security