节点文献

千兆广域网环境下信息检测系统的研究与实现

A Study on Information Detection and Analysis System for 1000M W-LAN

【作者】 李波

【导师】 戴宗坤; 姜万良;

【作者基本信息】 四川大学 , 电子与通信工程, 2005, 硕士

【摘要】 随着计算机技术的发展和互联网应用的日益普及,广域网运行中出现的非法入侵,尤其是来自网络内部的安全威胁日益增多。本文研究的问题是基于千兆级广域网平台的网络信息检测系统。该系统采用C/S通信模式建立网络系统和应用系统,是一个实时大流量网络信息流检测与管理工具,广泛适用于ISP级的网络信息检测(如EMAIL、HTTP、FTP、Telnet等)。该系统通过对网络中的数据包进行旁路侦听,实现对非法信息传播、涉密信息泄漏,以及对有害信息、黄色信息和反动信息的发现、跟踪、定位,记录和审计;系统可以按照用户定义的策略对海量数据进行信息过滤、分析和跟踪,也可根据用户定义的检测和分析策略对网络数据流进行还原、归类,并予以报警或响应。它是网络安全行业管理部门监督上网人员遵纪守法和网络数据检测取证的有效手段,也为网络信息系统的安全管理提供了技术依据。

【Abstract】 It is a key problem to monitor and analyze the information flow in Internet for the security administration, the system bases on path-by detection principle to gather,filter and analyze data of Internet . it is a client and sever platform enabled user to detect FTP ,TELNET, EMAIL , HTTP protocol data , find and locate the illegal targets and activities . The system passes to the data in the network a detection for proceeding bypass wiretapping, realizing to the illegal information spreads, keeping secret information leaking, and to harmful information, yellow information with reaction information, follow, fixed position, record with audit;The system can proceed to the amount of sea data according to the strategy that customer define the information filters and analyze with follow, and also can according to the examination that customer define with analyze the strategy to flow to the network data the proceeding restores, categorize, and give to report to the police or respond to.It is safe management offering that the valid means that the safe profession in network management section inspects the internet access personnel obey the law to take the certificate with the network data examination, and also for network information system technique according to.

  • 【网络出版投稿人】 四川大学
  • 【网络出版年期】2006年 07期
  • 【分类号】TP393.2
  • 【被引频次】1
  • 【下载频次】54
节点文献中: 

本文链接的文献网络图示:

本文的引文网络