节点文献
网络入侵防御系统(IPS)架构设计及关键问题研究
The Architecture Design of Intrusion Prevention System and the Research on Key Problems
【作者】 孙宇;
【导师】 孙济洲;
【作者基本信息】 天津大学 , 计算机系统结构, 2005, 硕士
【摘要】 随着计算机和网络技术的应用日益普及,各种网络安全问题也日益突出,为此人们开发出了许多针对具体安全问题的安全技术和系统。入侵检测系统(IDS)和防火墙是其中两种主要的网络安全技术。但是这二者都存在着各自的缺陷,不能很好地解决日趋严重的网络安全问题。本文首先介绍和分析了入侵检测系统和防火墙各自的原理和缺陷,并且分析了使用入侵检测系统与防火墙联动来防御网络攻击的方法在性能和可靠性方面的不足之处。随后,本文提出了融合审计和网络防御功能的入侵防御系统(IPS)的系统架构设计方案。该系统针对攻击防御任务的特殊要求,对探测攻击行为的检测分析组件进行优化,添加了攻击行为特征分析和防御策略生成模块; 策略执行组件使用专用防御引擎执行防御策略,为系统提供深层防御能力。分布式拒绝服务攻击(DDoS)是目前危害最严重,最难以防范的一种网络攻击方式。传统的入侵检测技术和防火墙技术都不能有效地对DDoS攻击进行防御。所以,对分布式拒绝服务攻击的防御是本文设计的入侵防御系统(IPS)需要解决的关键问题。本文系统地论述了DDoS攻击的现状、特点及形式,分析了现有防御技术的缺陷,提出了在特征分型的基础上,针对DDoS攻击的特殊行为模式进行防御的思想,并设计了基于状态控制机制和分级保护策略的DDoS攻击三层防御模型。本文实现了该防御模型中的关键模块,并通过实验证明了其有效性和可靠性。
【Abstract】 As the application of the computer and network technology is popularized day by day, various kinds of online security questions are outstanding day by day. There are two kinds of main network security practices among them: Intrusion Detection System (IDS) and Firewall. However, since of their own defects, they can’t solve the serious online security problems perfectly. Firstly, this paper introduces and analyses the principles and defects of Intrusion Detection System and Firewall, and analyses the weakness from performance and dependability of method that uses the interaction model to defend against the network attack, which combines the Intrusion Detection System and Firewall for defending issues. This paper designs the architecture of Intrusion Prevention System (IPS), which combines the audit function and defense function for particular defending requirements. This system optimizes the detection and analysis component based on the special demand of prevention task that is in charge of detecting intrusion issues and consists of intrusion signature analysis module and prevention policy creating module. Prevention policy execution component provides intensive defense by particular execution engine. The Distributed Denial of Service (DDoS) attack is one of the most serious network threats and the one that is most difficult to defend. The traditional technologies of Intrusion Detection System and Firewall can’t resist it effectively. Hence, it is recognized to be the key problem that how to create an available measure in Intrusion Prevention System to defend the DDoS attack effectively and adapably. This paper discusses the current status, features and forms of DDoS attack systematically and analysis the flaws of current defending practices. Basing on the behavior characteristic differentiation, this paper presents a defending theory that use different measures to defend the DDoS attack with different behavior patterns and creates a three-phase defending model basing on the state-control mechanism and phase-defending policy. This paper implements the main parts and the key modules of the DDoS defending model and proves the availability and stability of the model.
- 【网络出版投稿人】 天津大学 【网络出版年期】2006年 06期
- 【分类号】TP393.08
- 【被引频次】15
- 【下载频次】560