首页> 外国专利> Intrusion detection system and method based on kernel module in security gateway system for high-speed intrusion detection on network

Intrusion detection system and method based on kernel module in security gateway system for high-speed intrusion detection on network

机译:安全网关系统中基于内核模块的入侵检测系统和方法,用于网络高速入侵检测

摘要

PURPOSE: A kernel based fast IDS(Intrusion Detection System) of a security gateway and a method thereof are provided to offer a stable and improved performance by receiving a packet from a card device collecting the packet and performing filtering fast, and analyzing the packet in a kernel area. CONSTITUTION: A packet information extractor(210) transfers the packet information filtering the actually received network packet to an upper analysis module. A fast intrusion detecting tool(220) gives an alarm if intrusion is detected by comparing the packet information received from the packet information extractor with a previously defined intrusion pattern on a kernel level. A system controlling/managing tool(230) generates an alarm message of the alarm is received from the fast intrusion detecting tool and provides the information for updating the intrusion pattern to the fast intrusion detecting tool on an application level.
机译:目的:提供一种基于内核的安全网关的快速入侵检测系统(IDS)及其方法,以通过从收集数据包的卡设备接收数据包并进行快速过滤并分析数据包来提供稳定和改进的性能。一个内核区域。构成:分组信息提取器(210)将过滤实际接收到的网络分组的分组信息传送给上层分析模块。如果通过从分组信息提取器接收到的分组信息与在内核级别上预先定义的入侵模式进行比较,则快速入侵检测工具(220)发出警报。系统控制/管理工具(230)生成从快速入侵检测工具接收到的警报的警报消息,并在应用程序级别上向快速入侵检测工具提供用于更新入侵模式的信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号