首页> 外文会议>International conference on information and knowledge engineering >Design of Policy-based Security Management for Intrusion Detection
【24h】

Design of Policy-based Security Management for Intrusion Detection

机译:基于政策的入侵检测设计安全管理设计

获取原文

摘要

Intrusion Detection System (IDS) is a next generation security solution that minimizes the damage of hacking, in case a firewall fails in the isolation of intrusions, and responds the intrusion dynamically. Legacy security management is difficult to deal with changes in security environments, because it lacks of security policies and integrated security methods. In order to resolve these problems, we need policy-based security management (PBSM) that has standard security policy, consulting, diagnosis, maintenance, and repair function. It is necessary to monitor and control security services by PBSM. In this paper, we design and implement PBSM for intrusion detection. Our platform consists of a network node, general hosts and a management node. The network node is a security router that performs packet filtering, intrusion detection, intrusion analysis, intrusion response, and policy enforcement. The management node manages a network node and general hosts by security policies. We design the channel between a management node and a network node using Common Open Policy Service (COPS) and IP Security (IPsec). We have applied java and web to implementing GUI for PBSM. Java is used to program the user interface for PBSM. As the proposed system makes use of web, PBSM is easily accessed through the web remotely in real time. As the proposed system makes use of Web, security management system is easily accessed through the Web.
机译:入侵检测系统(IDS)是一个下一代安全解,以最大限度地减少黑客攻击的损坏,以防防火墙在隔离入侵时,动态响应入侵。遗留安全管理难以处理安全环境的变化,因为它缺乏安全策略和集成安全方法。为了解决这些问题,我们需要具有标准安全策略,咨询,诊断,维护和修复功能的基于策略的安全管理(PBSM)。有必要通过PBSM监控和控制安全服务。在本文中,我们设计并实现了用于入侵检测的PBSM。我们的平台包括网络节点,常规主机和管理节点。网络节点是一个安全路由器,用于执行分组过滤,入侵检测,入侵分析,入侵响应和策略实施。管理节点通过安全策略管理网络节点和常规主机。我们使用公共开放策略服务(COPS)和IP安全(IPSec)设计管理节点和网络节点之间的频道。我们已将Java和Web应用于PBSM的GUI。 Java用于对PBSM进行编程用户界面。由于所提出的系统利用Web,可以实时通过网站远程访问PBSM。由于所提出的系统利用Web,通过Web轻松访问安全管理系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号