节点文献
基于INTRANET的入侵防御系统模型的研究
Research and Realizing of Intrusion Prevention System Model Based on INTRANET
【摘要】 提出一种“检测防御—数据融合分析和数据挖掘—响应”多检测器数据融合和数据挖掘入侵防御模型。基于多检测器数据融合和数据挖掘的IPS,比现有单一的防护系统更为合理和有效,并在设计中对传统防火墙和入侵检测联动系统进行了技术上的改进,以解决INTRANET安全问题和传统IPS的漏报以及因误报而造成的新的DoS攻击等问题。而且这种设计的意义在于它具有普遍性,在同类企业网中可以根据自己的实际情况进行移植和应用。
【Abstract】 Based on detection prevention-data fusion analysis and data mining-response,a layered intrusion prevention system(IPS) model is proposed.The IPS based on multi-sensor data fusion and data mining has more reasonable and availability than single system.This work improves the traditional firework technology and intrusion detection system,solves the problem of intranet safety,failing to report and attacking with new DoS incurred because of it.The design is the generalization.So it can be extended to other enterprise easily.
- 【文献出处】 化工自动化及仪表 ,Control and Instruments in Chemical Industry , 编辑部邮箱 ,2006年02期
- 【分类号】TP393.08
- 【被引频次】7
- 【下载频次】121