资源描述:
《信息安全(入侵检测)》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、IntrusionDetectionSystemWhatisIDS?IDS=IntrusionDetectionSystemIntrusiondetectionsystems(IDSs)aresoftwareorhardwaresystemsthatautomatetheprocessofmonitoringtheeventsoccurringinacomputersystemornetwork,analyzingthemforsignsofsecurityproblems.NotfirewallWhyuseIDS?
2、Topreventproblembehaviors2.Todetectattacksandothersecurityviolationsthatarenotpreventedbyothersecuritymeasures3.Todocumenttheexistingthreattoanorganization,allowingimproveddiagnosis,recovery,andcorrectionofausativefactors.4.Toactasqualitycontrolforsecuritydes
3、ignandadministrationGeneralIDSModelSensorAnalyzerManagerOperatorAdministratorBasicClassificationNIDS-NetworkBasede.g.CiscoSecureIDS,AxentNetpowler,Snort,ISSRealSecureNetworkSensor,NAICybercopMonitorHIDS-HostBasede.g.AxentIntruderAlert,ISSRealSecureOSSensor,Tri
4、pwireBasedondifferentdataresourceNIDS-NetworkBasedNIDSdetectattacksbycapturingandanalyzingnetworkpackets.Listeningonanetworksegmentorswitch,onenetwork-basedIDScanmonitorthenetworktrafficaffectingmultiplehoststhatareconnectedtothenetworksegment,therebyprotec
5、tingthosehosts.monitoralargenetwork.littleimpactuponanexistingnetwork.·verysecureagainstattackandevenmadeinvisibletomanyattackers.AdvantagesofNetwork-BasedIDS·Network-basedIDSsmayhavedifficultyprocessinghightraffic.·ManyofNIDSsdon’tapplytoswitch-basednetworks
6、.·Network-basedIDSscannotanalyzeencryptedinformation.·NIDSshaveproblemsdealingwithnetworkbasedattacksthatinvolvefragmentingpackets.DisadvantagesofNetwork-BasedIDSs:Host-basedIDSsoperateoninformationcollectedfromwithinanindividualcomputersystem.Host-BasedIDSsH
7、ost-basedIDSsnormallyutilizeoperatingsystemaudittrails,andsystemlogsasinformationsourcesHIDScandirectlyaccessandmonitorthedatafilesandsystemprocesses,soanalyzeactivitieswithgreatreliabilityandprecision,Host-basedIDSscanoperateencryptednetworktrafficHost-basedI
8、DSsareunaffectedbyswitchednetworks.·WhenHost-basedIDSsoperateonOSaudittrails,theycanhelpdetectTrojanHorseorotherattacksthatinvolvesoftwareintegritybreaches.AdvantagesHIDSa