摘要
首先分析了Snort网络入侵检测系统,然后剖析了ARP协议工作原理及ARP欺骗攻击的过程。根据校园网的网络结构特点,在网关上安装Snort,通过修改Snort配置文件,添加输出ARP头部信息的Snort输出插件,实现对校园网ARP欺骗的检测预防。
This paper first analyzes the network intrusion detection system Snort,then analyzes the ARP agreement working principle and process of ARP spoofing attack.According to the characteristics of campus network structure,installed in the gateway Snort,by modifying Snort configuration files,add output of ARP header information Snort output plug-in ARP deception of campus network,realize the detection prevention.
出处
《计算机安全》
2011年第7期61-63,共3页
Network & Computer Security