|
Intrusion detection systems often include event is generated, the event analyzer, the response unit, and a four-part event database. Event Analyzer is a key part of our intrusion detection technology. In the event of network intrusion detection system analyzer, intercept every packet network, the analysis should be carried out to match, which takes a lot of time and system resources. Most of the existing network intrusion detection dozens of megabytes of detection speed large number of applications, with hundreds of megabytes or even gigabit network intrusion detection speed has lagged far behind the speed of the network. For this detection speed bottleneck, which we improved AC-BM algorithm to solve this problem. Addition to intrusion detection system, our computers may also use a firewall, vulnerability scanning, and other categories of safety equipment, how to exchange information between the security components, and work together to find the attacker, respond to and prevent attacks related to the entire system security. In addition, the detection of spyware and adware is also a headache. AC-BM algorithm, we improved on the basis of the establishment of a proactive defense module with active defense capabilities in order to solve the problem. The general concept of intrusion detection systems, models, classification of intrusion detection technology. Then describes the CIDF model of network intrusion detection system and intrusion detection weaknesses and limitations, which leads to the significance of status and background of our research. Describes the principle of the data acquisition. Because I was under the Linux operating system, use the the libpcap library function to achieve packet capture, so we to introduce Libpcap the relevant functions and data structures. Focuses on the network packet capture program, and output experimental results. A brief introduction of TCP / IP four-layer model, the the datagram encapsulation process, IP, TCP, and other protocols, formats and data structure. These are very important because they are Datagram Protocol analysis must load analysis. Of course, the focus is placed on the principle of the introduced data analysis, module design, program implementation, the final output of the experimental data. Our own improved algorithm. Focuses on how to improve the AC-BM algorithm, to introduce it works, a detailed description of the algorithm, test results, and results analysis. The formation of active defense module, use it to achieve the multi-layered defense-in-depth, interactive and other security devices, to explore the detection of anti-scan, anti-spyware, anti-adware. Finally, conclusions and the need to further improve the work in the future.
|