校園網(wǎng)入侵檢測系統(tǒng)設(shè)計(jì)與實(shí)現(xiàn)
[Abstract]:Campus network is an important infrastructure of the school. It can facilitate students to study, discuss problems and consult information. It is also a platform for teaching, management and communication. However, the security problems caused by accessing Internet bring great challenges to our campus network managers. The hacker tools available everywhere and the system vulnerabilities exposed constantly make our campus network in danger all the time. The safety of campus network plays an important role in maintaining normal teaching order and resource management. Therefore, how to ensure the security of campus network has become an extremely important issue. In this paper, the current situation of intrusion detection technology research at home and abroad is discussed, and the deficiency of existing intrusion detection system is analyzed, and the function of intrusion detection system in campus network is also analyzed. Firstly, a typical network intrusion detection system (snort) is taken as the research object, and the distributed intrusion detection system (DIDS) model with snort as the core is designed. The accuracy and efficiency of intrusion detection are improved by protocol analysis and pattern matching. The system mainly includes data capture module, data server module, security communication module and response module. The practical problems of data capture module are analyzed, including packet capture, protocol analysis, pattern matching, rule list generation and so on. Among them, the Snort rule set is used, the database is My SQL database, and the graphical output of ACID analysis is realized. It is convenient for users to configure and master the security situation of the system. Finally, this paper uses the Snort software based on Linux to build the distributed intrusion detection system test platform, gives the detailed configuration list of the IDS host, server and management console, and carries out the test and analysis. It shows that the system is feasible and effective.
【學(xué)位授予單位】:電子科技大學(xué)
【學(xué)位級(jí)別】:碩士
【學(xué)位授予年份】:2010
【分類號(hào)】:TP393.18
【參考文獻(xiàn)】
相關(guān)期刊論文 前10條
1 陳海濤,裴晉澤,胡華平,龔正虎;基于對(duì)等網(wǎng)絡(luò)的自適應(yīng)安全協(xié)作框架研究[J];北京航空航天大學(xué)學(xué)報(bào);2004年11期
2 張秀玲;神經(jīng)網(wǎng)絡(luò)自適應(yīng)控制的研究進(jìn)展及展望[J];工業(yè)儀表與自動(dòng)化裝置;2002年01期
3 郭曉淳,吳杰宏,劉放;入侵檢測綜述[J];沈陽航空工業(yè)學(xué)院學(xué)報(bào);2001年04期
4 李曉鶯,曾啟銘;利用協(xié)議分析提高入侵檢測效率[J];計(jì)算機(jī)工程與應(yīng)用;2003年06期
5 ;NAI的CyberCop Scanner在InfoWorld評(píng)測中勝出CyberCop Scanner榮獲安全漏洞檢測最佳整體解決方案殊榮[J];計(jì)算機(jī)與通信;1999年04期
6 ;思科:積極推動(dòng)下一代廣電網(wǎng)絡(luò)發(fā)展[J];通訊世界;2010年04期
7 張海芹;須文波;;基于移動(dòng)Agent的新型分布式入侵檢測系統(tǒng)[J];微計(jì)算機(jī)信息;2006年24期
8 連一峰;入侵檢測綜述(三)[J];網(wǎng)絡(luò)安全技術(shù)與應(yīng)用;2003年03期
9 徐健;張順頤;;基于網(wǎng)絡(luò)的入侵檢測系統(tǒng)的設(shè)計(jì)與實(shí)現(xiàn)[J];計(jì)算機(jī)系統(tǒng)應(yīng)用;2006年10期
10 ;啟明星辰:可視化將IDS帶入新時(shí)代[J];信息網(wǎng)絡(luò)安全;2010年04期
相關(guān)碩士學(xué)位論文 前1條
1 鐘平;校園網(wǎng)安全防范技術(shù)研究[D];廣東工業(yè)大學(xué);2007年
,本文編號(hào):2283775
本文鏈接:http://www.sikaile.net/guanlilunwen/ydhl/2283775.html