• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (1): 32-34.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • 上一篇    下一篇

基于脚本的千兆位入侵防御开放模型研究

  

  1. 梁波
  • 收稿日期:2008-08-03 修回日期:2008-11-06 出版日期:2010-01-18 发布日期:2010-01-18
  • 通讯作者: 650051 云南省昆明市昆明理工大学新迎校区云南省计算机重点实验室318 E-mail:lb@cnlab.net
  • 作者简介:梁波(1977-)男,重庆人,硕士生,研究方向为网络安全;邓辉,副教授;王锋,教授。

Research on the MegaBits Network Environment’s Open Model of IntrusionPrevention Systems Based on the Script

  1. (Yunnan Provincial Key Laboratory for Computer Technology Application,Kunming Universuty of Science and Technology,Kunming 650051,China)
  • Received:2008-08-03 Revised:2008-11-06 Online:2010-01-18 Published:2010-01-18

摘要:

文着眼于提高入侵防御系统[1]的检测速度和精准度[2],遵循通用入侵检测框架(CIDF)[3]规范,依据基于网络的入侵检测系统(NIPS)的结构要求,依据层次化结构设计的思想,自底向上依次分为数据采集模块、事件生成引擎、策略脚本解释器和入侵防御模块四个部分。最后利用脚本描述,实现一个千兆环境下入侵防御集群开放模型。

关键词: 入侵防御;动态协议探测;正则匹配;开放;脚本描述

Abstract:

Based on the Common Intrusion Prevention Framework (CIDF) and the NetworkBased Intrusion Prevention System (NIPS) standards, we present an intrusion prevention system called Gigabits IPS (GIPS), which is used to improve the prevention speed and accuracy, and to ensure highspeed network monitoring. The GIPS consists of the data capture module, the event generation engine, the policy script interpreter and the intrusion prevention module. With the script description, we implement a megabits network environment's cluster open model of intrusion prevention systems.

Key words: intrusion prevention;dynamic protocol detection;regular match;open;script description

中图分类号: