节点文献

智能网络取证系统

Intelligent Network Forensic System

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 高献伟郑捷文杨泽明许榕生

【Author】 GAO Xian-wei~ 1,2 , ZHENG Jie-wen~2, YANG Ze-ming~2, XU Rong-sheng~2(1. Graduate School of the Chinese Academy of Sciences, Beijing 100039,China;2.Computer Center, Institute of High Energy Physics, CAS, Beijing 100039,China)

【机构】 中国科学院研究生院中国科学院高能物理研究所计算中心中国科学院高能物理研究所计算中心 北京100039北京100039

【摘要】 智能网络取证为网络防护提供了一种新的措施,弥补了原有网络安全体系中的不足。该系统包括数据采集、数据过滤、数据存储、管理控制和智能取证分析等部分。在数据获取的时候采用了规则过滤机制,减少了系统的负载,提高了电子证据的精确性。在数据获取的时候,系统采用了TCP/IP的实时重组,可以对应用层数据进行过滤和检测。对于获得的数据,分析模块采用多种方式综合分析入侵行为,包括协议分析、专家系统、应用数据还原、入侵检测等技术。在网络环境中,它与IDS,防火墙,VPN等技术结合,可以提供更加安全可靠的防护体系。

【Abstract】 Intelligent network forensic system (INFS) gives us a new method of network protection, and remedies the shortage of the current network security system . The system consists of 5 parts including data collection, data filtering, data storage, management control and intelligent forensic analysis. Filtering rules are used for data collection, reducing the system work, and improving the reliability. The packages of TCP/IP are rebuilt to filter the application layer data. Many methods are used in analysis model to detect intrusion actions, such as protocol analysis, expert system, application layer data reconstruction, intrusion detection. In the network environment, INFS is combined with IDS, firewall, and VPN to serve us a more dependable and strong network security protection system.

【基金】 国家重点基础研究发展规划(973)项目(G1999035806)
  • 【文献出处】 计算机仿真 ,Computer Simulation , 编辑部邮箱 ,2006年03期
  • 【分类号】TP319
  • 【被引频次】16
  • 【下载频次】280
节点文献中: