论文部分内容阅读
入侵检测是网络安全的一个重要组成部分,它通过对计算机网络和主机系统中的关键信息进行实时采集和分析,从而判断出非法用户入侵和合法用户滥用资源的行为,并做出适当响应。它在传统技术的基础上,实现了检测与响应,使得对网络安全事故的处理由原来的事后发现发展为事前报警、自动响应。阐述了入侵检测技术的研究历史与背景,入侵检测的原理及方法,并讨论了该领域尚存的问题及其发展方向。
Intrusion detection is an important part of network security. It collects and analyzes the key information in computer network and host system in real time to determine the illegal user intrusion and legal user abuse of resources, and make appropriate response. Based on the traditional technology, it realizes the detection and response, which makes the handling of network security accidents develop from the original after-event alarm to the prior warning and automatic response. The research history and background of intrusion detection technology, the principle and method of intrusion detection are expounded. The existing problems in this field and their developing direction are also discussed.