论文部分内容阅读
针对单一技术在网络安全防御上的局限性,提出了用防火墙、入侵检测系统(Snort)、蜜罐三种技术组成共同对抗网络入侵的联动式防御系统。联动系统增加了入侵检测系统的联动插件,扩展了防火墙动态加入重定向规则功能,设置了蜜罐主机监视攻击,实现了三者的紧密互动。介绍了系统的结构、工作流程以及联动方案,并做了攻击实验,结果证明,联动防御系统对大规模的蠕虫攻击能够即时抵制。
Aiming at the limitations of single technology in network security defense, this paper proposes a joint defense system that uses firewall, intrusion detection system (Snort) and honeypot together to counter network intrusion. The linkage system adds intrusion detection system linkage plug-ins, expands the dynamic firewall to join the redirection rules function, set up a honeypot host monitoring attacks, to achieve a close interaction between the three. Introduced the system structure, workflow and linkage scheme, and did the attack experiment, the result proves that the linkage defense system can instantaneously resist the large-scale worm attack.