摘要
针对小型电子商务系统的应用特点,分析该如何设计适合于它的入侵检测系统。为此,深入学习了Windows系统信息,采用了误用检测中的模式匹配和异常检测中的统计与数据挖掘方法来进行异常检测。最终,提出了一种基于主机的分布式入侵检测系统。通过测试发现,该体系结构的入侵检测系统能防范内外部攻击,并可以和防火墙联动,在发生异常时,使系统所受的损失最小,适用于基于windows平台的小型的电子商务系统。
In this paper , we learned how to design an Intrusion Detection System(IDS) for e-business system. Therefore, I learned system information of Windows OS. In the implementation of the IDS, the pattern matching of Misuse detection and Statistic and Data Mining of Anomaly detection were both used. In the end, it was brought forward a new architecture for the IDS- a distributed host-computer-based IDS. By tested,we could find that this IDS can prevent both exterior and inner attack. It could effectively reduce loss of host computer by link itself with firewall when abnormal happened. In fact, this new architecture IDS will best apply in a Windows OS platform for an e-business system.
出处
《电脑开发与应用》
2007年第12期13-14,共2页
Computer Development & Applications
基金
山西交通职业技术学院科研基金资助项目
关键词
入侵检测
分布式
模式匹配
异常检测
入侵响应
intrusion detection, distributed ,pattern matching ,anomaly detection ,intrusion response