首页> 美国政府科技报告 >Tuning Intrusion Detection to Work with a Two Encryption Key Version of IPsec.
【24h】

Tuning Intrusion Detection to Work with a Two Encryption Key Version of IPsec.

机译:调整入侵检测以使用两个加密密钥版本的Ipsec。

获取原文

摘要

Network-based intrusion detection systems (NIDSs) are one component of a comprehensive network security solution. The use of IPsec, which encrypts network traffic, renders network intrusion detection virtually useless unless traffic is decrypted at network gateways. Host-based intrusion detection systems (HIDSs) can provide some of the functionality of NIDSs but with limitations. HIDSs cannot perform a network-wide analysis and can be subverted if a host is compromised. We propose an approach to intrusion detection that combines HIDS, NIDS, and a version of IPsec that encrypts the header and the body of IP packets separately (“Two-Zone IPsec”). We show that all of the network events currently detectable by the Snort NIDS on unencrypted network traffic are also detectable on encrypted network traffic using this approach. The NIDS detects networklevel events that HIDSs have trouble detecting and HIDSs detect application-level events that can’t be detected by the NIDS.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号