节点文献

基于Snort的入侵检测系统在校园网中的应用研究

Research on Application of Intrusion Detection System Based on Snort in Campus Network

【作者】 林文卿

【导师】 王培东; 何云斌;

【作者基本信息】 哈尔滨理工大学 , 计算机技术, 2007, 硕士

【摘要】 近年来,随着网络技术的迅猛发展和因特网的广泛普及,网络安全问题变得日益突出,网络安全的一个主要威胁就是通过网络对信息系统的入侵。作为网络安全的一个重要组成部分,网络入侵检测系统(NIDS)也越来越显示出其重要性。高等院校是新技术的孕育基地,随着信息化时代的到来,高等院校也在推进自己的信息化建设。随着校园网络规模的不断扩大,校园网络的安全问题也日益突出。仅仅依靠传统的防火墙技术并不能保证校园网络的安全。为此,本文提出使用入侵检测系统和防火墙相结合得方法实现校园网络的安全防护。NIDS能够监视网络数据流动情况,当入侵发生时能够提供报警。现在已经出现了很多商业的NIDS,但是它们大多比较复杂,比较难以掌握,而且比较昂贵,比较小的公司无法承受。Snort2.0是一个出色的免费NIDS系统,它基于GPL,是一个强大的轻量级的网络入侵检测系统。本文首先介绍了入侵检测系统的分类,当前的研究现状,以及使用的主要技术和发展趋势。之后介绍了Snort2.0的体系结构、技术特点及其完成的功能,重点研究Snort2.0规则的组成、设置与运行情况;在此基础上提出了将Snort2.0入侵检测系统应用于校园网络中以保障校园网络的安全;给出了Snort2.0入侵检测系统在校园网络中的配置方案、安装使用方法、以及运行和测试方法。经应用实验表明,在校园网中使用基于Snort2.0入侵检测系统可以有效的保证校园网络的安全可靠。

【Abstract】 In recent years, with the rapid development of the network technology andthe extensive popularization of Internet, the security of network becomes moreand more important. A main threat of the network security is to invade to theinformation system through network. As one important component of networksecurity, the Network Intrusion Detection System (NIDS) becomes more andmore important.Colleges and universities are a breeding base of the new technology. Withthe arrival of the information era, they are promoting their own informationconstruction. As the scale of the campus network becomes bigger and bigger, itssecurity problem will be more and more serious. Depends upon the traditionalfirewall technology can not be able to guarantee the campus network. Therefore,this article proposed the method of combining the NIDS and the firewall torealize the campus network safe protection. NIDS which is used for monitoringthe network data flow can alert when the intrusion happens. Already NIDS ofmuch commerce has appeared now, but they are mostly more complicated, moredifficult to master, and more expensive, and the smaller companies are unable tobear.Snort2.0 is an outstanding and free NIDS system, which based on GPL, andit is also a strong NIDS of lightweight. Firstly this text introduces theclassification of the intrusion detection system, the current research circumstance,the trend of development and the technology used mostly. Secondly, this textintroduces the system architecture, technological characteristics and functions ofSnort2.0 IDS, mainly research the construction of the system, establishment andrunning of Snort 2.0 Intrusion Detection Rules. On the basis of study andexperiment, the paper proposes a design which uses Snort 2.0 in compus network to protect its security. Meanthwhile, the configuration scheme, the method ofinstalling and using, the situation of running and test of the Snort2.0 IDS incampus network are given.The application and test result shows that, the NIDS based on snort2.0 canguarantee the campus network well.

【关键词】 入侵检测Snort规则设置校园网
【Key words】 Intrusion detectionSnortRules settingCampus network
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】404
节点文献中: 

本文链接的文献网络图示:

本文的引文网络