硕士论文-基于tcpip协议分析的入侵检测系统研究与实现
ABSTRACT
Withtherapiddevelopmentofcomputerandcommunicationtechnology,computersystemhasbeendevelopedfromindependenthosttocomplexandinterconnectsnetworks.Itbringsgreatconveniencetopeopleforsharingofinformation-Butalongwiththegreatbenefitofintemct,italsobringsnewthreats.Problemsonsecurityofintemetarebecomingveryserious.Thustheresearchofcomputernetworksecurityisalsobecomingveryimportant.
Firstly,thethesisanalyzesthegoalofcomputernetworksecudtyandthesecuritythreatofnetworkfaced,andthenintroducesseveraltraditionalsecuritytechniquessuchasdataencryptiontechniquesandfireworktechniques.Itanalyzestheproblemsofthesetraditionalsecuritytechniquesandbringsforwardcombine/ntmsiondetectionsystem(10S)andthetraditionalnetworksecuritytechniquestocreatemulti—layersrecoverysystem.ItindicatesthestatusinsecuritydomainanditssignificanceofloS.Secondly,thethesisgoesdeepintoparticularslOSindetails,frombasicconcept,modelandtheory.Thirdly,thethesisanalyzesthefrangibilityoftheTCP/IPprotocolandthenon—securityofInteractbehindit.Afterward,thethesisexpatiatesonthedesignthoughtandimplementationmethodofdistributedlOSwithCIDFframeworkbasedonprotocolanalysis.ThesystemhasbeenappliedtoI.ANofChengduSunriseInformationTechnologyCO.,LTD.
ThecoresoftheloSarereal timeandveracity.Withthedevelopmentofhighspeednetwork,thethroughoutofnetworkbecomesgreat.Itisthepresentfocushowtodetectthepacketofdatainnetworkinrealtimeandveracity(falsepositivesandfalsenegative).TheIDSdesignofthisthesisisbasedontheabovepoints.Itaimedatimprovingitsdetectingspeedandexactness.
Intheend,thethesisdiscussestheresearchstatusandfuturedevelopmentofloS.KeyWords:networksecurity,intrusiondetection,protocolanalysis,multi—patternmatchII