摘要
针对专业教学过程中理论内容较难理解和接受的情况,设计了一种入侵检测的实验系统,实现对网络嗅探和端口扫描两种类型的入侵进行检测。针对网络中的嗅探攻击,利用WinPcap网络开发包,实现基于ARP报文探测的嗅探攻击的演示。此外,实验系统还针对网络中的TCP端口扫描攻击,利用Libnids网络开发包,实现了基于统计阈值检测法的TCP端口扫描攻击的演示。最终通过短消息模块实现相应入侵行为的短信通知。
In view of the situation that content of the theory is difficult to understand and accept in the process of teaching professional lesson,an intrusion detection experiment system is implemented,which is realized in two kinds of intrusion detection,such as network sniffer and port scan.Using the WinPcap network development kit,and based on the ARP packet detection,the system demonstrates how the sniffer attacks work in the network.Using the Libnids network development kit,and based on the detection method of statistical threshold,the system also demonstrates how the TCP port-scans attack in the network.As being attacked,a corresponding notification could be sent to the manager through SMS modules.
出处
《计算机教育》
2010年第6期154-157,96,共5页
Computer Education
基金
南京邮电大学教学改革研究项目(JG00407JX22)
关键词
入侵检测
实验系统
网络嗅探
端口扫描
intrusion detection
experiment system
network sniffer
port scan