• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2005, Vol. 27 ›› Issue (11): 6-8.

• 论文 • 上一篇    下一篇

高速网络安全监控系统的设计与实现

周金泉[1,2] 郑挺[1] 胡华平[1]   

  • 出版日期:2005-11-01 发布日期:2010-06-24

  • Online:2005-11-01 Published:2010-06-24

摘要:

随着计算机网络的发展,对高速网络的安全进行监控变得越来越重詈。结合实际需求,本文提出了一些重要的设计思想,实现与测试了一个基于高速网络关键点捕获,对网络 攻击进行实时检测、预警和响应的高速网络安全监控系统原型,有效地解决了目前高速网络安全监控系统存在的一些难题。目前,该系统原型已经在实际中得到成功应用。

关键词: 攻击检测 报警分析 报文捕获 报文存储 安全监控

Abstract:

With the development of computer network, it is more and more important to monitor the security of high-speed networks. Combining with the de-facto de mands, some useful ideas are presented in the paper. A prototype system is implemented and tested, which is a high-speed network security monitoring sys  tem based on key point capturing, real-time detection, early-warning and reaction to various network attacks. The system effectively resolves some Cruci al problems which exist in high-speed network security monitoring systems nowadays. This prototype system has been applied to network security monitorin g successfully.

Key words: (attack detection;alert analysis, packet capturing, packet storage, security monitoring)