论文部分内容阅读
网络入侵检测系统用来监视网络数据流动情况,当入侵发生时能够提供报警。Snort允许管理员在短时间内通过修改配置进行实时的安全响应。详细介绍了Snort的体系结构、入侵检测机制以及规则的定义、构成和更新,简要介绍了Snort的内置应用。Snort因其具有开放源代码、轻量而功能强大、可移植性强、检测规则简单而有效、允许使用者完全定制自己的规则等特点而有很好的应用前景。
Network intrusion detection system used to monitor network data flow, when the invasion can provide an alarm. Snort allows administrators to make real-time security responses by modifying their configuration in a short period of time. Details Snort’s architecture, intrusion detection mechanism and rules of the definition, composition and update, a brief introduction to Snort’s built-in applications. Snort has good application prospects because of its open source, lightweight and powerful, portability, simple and effective detection rules, and the ability to allow users to fully customize their own rules.