【24h】

An Enhanced Three Levels Security Policy

机译:增强的三级安全策略

获取原文
           

摘要

Design and implementation of intrusion detection systems remain an important research issue in order to maintain proper network security. Despite the undeniable progress in the area of computer security there is still much to be done to improve security of todaya€?s computer systems and so many mechanisms have been developed to assure its security.These systems are vulnerable to attacks from both non-authorized users (outsidera€?s attacks) as well as attacks from authorized users (insidersa€? attacks) who abuse their privileges. Many researches have proved that more than 60% of the attacks come from the inside of the computer systems.In the previous article [1], we have proposed an exact algorithm for the deployment of security policies for single computer systems but in this paper, we will propose an approach for complex computer systems, base on a three levels security policy. Each level will protect the computer system from both outsidersa€? attacks and insidersa€? attacks. This global security policy will allow the administrator of the security systems not only to detect attacks, but also to warn him about this intrusion and forbid access to the whole networks.
机译:为了维护适当的网络安全性,入侵检测系统的设计和实现仍然是一个重要的研究课题。尽管在计算机安全领域取得了不可否认的进步,但是要改善当今计算机系统的安全性仍然有许多工作要做,因此已经开发出许多机制来确保其安全性。这些系统容易受到来自未经授权的攻击用户(外部攻击)以及来自滥用权限的授权用户的攻击(内部攻击)。许多研究证明,超过60%的攻击来自计算机系统内部。在先前的文章[1]中,我们提出了一种用于部署单个计算机系统安全策略的精确算法,但在本文中,我们将基于三级安全策略提出一种用于复杂计算机系统的方法。每个级别都将保护计算机系统免受外部人员的侵害。攻击和内部人员?攻击。这种全局安全策略将使安全系统的管理员不仅可以检测到攻击,还可以警告他有关这种入侵并禁止访问整个网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号