Dissertation > Excellent graduate degree dissertation topics show

Application Study of Intrusion Detection System and Firewall under Separation-and-Mapping Network

Author: ZhangShaoWei
Tutor: ZhangSiDong
School: Beijing Jiaotong University
Course: Communication and Information System
Keywords: Separation mechanism network Network Security Intrusion Detection System Firewall
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 93
Quote: 1
Read: Download Dissertation

Abstract


With the advent of network-centric information age, the Internet, the rapid pace of development in a short period of decades, led to the tremendous progress of society as a whole. In recent years the number of access terminals is rapidly expanding Internet access to mobile development from simple static access. Resulting complex environment Internet and network security issues. The separation mechanism Networks host identity and location separation of design ideas, the Internet system is divided into two parts for the access network and the core network, a good solution to the expansion of the Internet and mobility. But under the new network system security study also were not heeded. How to apply intrusion detection systems and firewall systems to detect intrusions and to respond effectively in real time to ensure the safety of the access network and the core network, the new network mechanisms has important significance. In this background, the separation mechanism network access network security issues, proposed separation mechanisms, intrusion detection systems and firewall applications and the specific implementation and verification program. The first, an overview of the specific theory of the separation mechanism of network technology, intrusion detection and firewall technology. On this basis, in-depth analysis of the advantages and problems of security access network separation mechanism. Analysis to understand the separation mechanism for network intrusion detection and firewall systems, possible intrusion analysis, drawn from a number of programs in the discussions separation mechanism to access network security enhancement program: the access network intrusion detection based network intrusion system behavior, firewall control communication network with traffic, IDS and firewall linkage severe real-time blocking access network intrusion, security protected access routers and core network based Host Intrusion Detection System. The program takes full advantage of the characteristics of intrusion detection and firewall, not only to achieve the full range of security detection and control access network separation mechanism is to achieve the purpose of by protecting access router to protect the core network and take preventive measures. For the realization of the program, select the intrusion detection system the OSSEC Host-based, network-based intrusion detection system snort under Linux the firewall iptables and snort / iptables linkage module snortsam applied research. In order to verify achieve results in the separation mechanism prototype network functional verification and testing of three parts: the separation mechanism IPv4 and IPv6 access network intrusion detection; the separation mechanism IPv4 severe real-time intrusion blocking access network; access router core network intrusion protection and real-time response. The results show that the system has reached a preliminary functional requirements of the design. Intrusion detection and firewall system performance management program to start in the follow-up work should enhance the separation mechanism, based on distributed systems, private security network and client / server mode, the large-scale application deployment capabilities.

Related Dissertations

  1. The Research of Malware Detection Technology Based on Active Mode,TP393.08
  2. Topology Measurement and Security Analysis on Gnutella and eMule Network,TP393.08
  3. Region-based wireless sensor network key management scheme for research,TP212.9
  4. SX Provincial Public Security Bureau Network Security Corps Performance Evaluation Index System Design,D631.1
  5. Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
  6. The Research of Insurance Network Marketing of China Insurance Company,F724.6
  7. Research and Implemention of Information Security Encryption System Based on the RSA,TP309.7
  8. The Research of Attack Source Traceback in Distributed Denial-of-Service Attacks Based on VoIP,TP393.08
  9. Research on Streaming Media Detection Methods Against DoS\DDoS Attack Based on Analysis of Self-similarity,TP393.08
  10. Design and Implementation of Assistant Management System Server Based on Hardware Firewall,TP393.08
  11. Firewall and three switch - based campus network security policy research,TP393.08
  12. Gansu Fuyuan Chemical analysis and design of integrated office platform,TP311.52
  13. Research and Design of Secure Comunication of NVD on Demand System,TP309
  14. The Design and Implementation of A Military University Network in Security and Reliability,TP393.18
  15. QH Software Services Marketing Strategy,F426.672
  16. Fast protocol identification based firewall system design and implementation,TP393.08
  17. IPsec-based remote access to corporate network systems design and implementation,TP393.08
  18. Behavior -based botnet detection method,TP393.08
  19. Based on TCP / IP, no shaft offset Remote Monitoring System Design,TP277
  20. Study browser security issues and solutions,TP393.092
  21. The Research of Security Issues in Cognitive Radio Networks,TN915.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile