J4 ›› 2010, Vol. 32 ›› Issue (1): 32-34.doi: 10.3969/j.issn.1007130X.2010.
• 论文 • 上一篇 下一篇
收稿日期:
修回日期:
出版日期:
发布日期:
通讯作者:
作者简介:
Received:
Revised:
Online:
Published:
摘要:
文着眼于提高入侵防御系统[1]的检测速度和精准度[2],遵循通用入侵检测框架(CIDF)[3]规范,依据基于网络的入侵检测系统(NIPS)的结构要求,依据层次化结构设计的思想,自底向上依次分为数据采集模块、事件生成引擎、策略脚本解释器和入侵防御模块四个部分。最后利用脚本描述,实现一个千兆环境下入侵防御集群开放模型。
关键词: 入侵防御;动态协议探测;正则匹配;开放;脚本描述
Abstract:
Based on the Common Intrusion Prevention Framework (CIDF) and the NetworkBased Intrusion Prevention System (NIPS) standards, we present an intrusion prevention system called Gigabits IPS (GIPS), which is used to improve the prevention speed and accuracy, and to ensure highspeed network monitoring. The GIPS consists of the data capture module, the event generation engine, the policy script interpreter and the intrusion prevention module. With the script description, we implement a megabits network environment's cluster open model of intrusion prevention systems.
Key words: intrusion prevention;dynamic protocol detection;regular match;open;script description
中图分类号:
TP393
梁波, 邓辉, 王锋. 基于脚本的千兆位入侵防御开放模型研究[J]. J4, 2010, 32(1): 32-34.
LIANG Bei, DENG Hui, WANG Feng. Research on the MegaBits Network Environment’s Open Model of IntrusionPrevention Systems Based on the Script[J]. J4, 2010, 32(1): 32-34.
0 / / 推荐
导出引用管理器 EndNote|Ris|BibTeX
链接本文: http://joces.nudt.edu.cn/CN/10.3969/j.issn.1007130X.2010.
http://joces.nudt.edu.cn/CN/Y2010/V32/I1/32