首页> 外国专利> Intrusion Detection System using the Multi-Intrusion Detection Model and Method thereof

Intrusion Detection System using the Multi-Intrusion Detection Model and Method thereof

机译:使用多入侵检测模型的入侵检测系统及其方法

摘要

PURPOSE: A system and a method for detecting the intrusion using the diverse intrusion detection models are provided to detect a case violating a security policy set by introducing a traditional access control technology to the intrusion detection system. CONSTITUTION: The intrusion detection system comprises a data collector, a data filtering and condensing part(230), an intrusion detector(240), a warning and reporting part, and an intrusion responding part(260). The data collector collects all traffics to a network having a monitoring target server(210) from an external or internal network(200) and transfers the collected data to the data filtering and condensing part. The data filtering and condensing part filters only the traffics to a monitoring target system, and converts and condenses the data to detect the intrusion by extracting the data necessary for the intrusion detection. If the intrusion detector judges the intrusion, the warning and reporting part reports the warning and the related inspection records and the intrusion responding part carries out the defined responding activity such as the environment resetting of the access control system.
机译:目的:提供一种使用多种入侵检测模型来检测入侵的系统和方法,以通过将传统的访问控制技术引入入侵检测系统来检测违反安全策略集的案件。构成:入侵检测系统包括数据收集器,数据过滤和压缩部分(230),入侵检测器(240),警告和报告部分以及入侵响应部分(260)。数据收集器从外部或内部网络(200)收集到具有监视目标服务器(210)的网络的所有业务,并将收集的数据传送到数据过滤和压缩部分。数据过滤和压缩部分仅过滤到监视目标系统的流量,并通过提取入侵检测所需的数据来转换和压缩数据以检测入侵。如果入侵检测器判断出入侵,则警告和报告部分会报告警告和相关的检查记录,并且入侵响应部分将执行定义的响应活动,例如访问控制系统的环境重置。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号