请下载论文,论文或程序为doc或rar格式,只上传部分目录查看,如果需要此论文或程序,请点击-下载论文,下载需要资料或是论文。个人入侵检测系统的实现-论文和程序及源代码
gerenruqinjiance-system-deshixian-lunwenhechengxujiyuandaima,因文件夹或是目录太多,只读取5个文件显示,需要就下载参考
包括目录名称:
个人入侵检测系统的实现-论文和程序及源代码 - 1 文件数, 0 目录数.
个人入侵检测系统的实现.doc
..\个人入侵检测系统的实现.doc
要
入侵检测系统(IDS)可以对系统或网络资源进行实时检测,及时发现闯入系统或网络的入侵者,也可预防合法用户对资源的误操作。本论文从入侵检测的基本理论和入侵检测中的关键技术出发,主要研究了一个简单的基于网络的windows平台上的个人入侵检测系统的实现(PIDS,Personal Intrusion Detection System)。论文首先分析了当前网络的安全现状,介绍了入侵检测技术的历史以及当前入侵检测系统的关键理论。分析了Windows的网络体系结构以及开发工具Winpcap的数据包捕获和过滤的结构。最后在Winpcap系统环境下实现本系统设计。本系统采用异常检测技术,通过Winpcap截取实时数据包,同时从截获的IP包中提取出概述性事件信息并传送给入侵检测模块,采用量化分析的方法对信息进行分析。系统在实际测试中表明对于具有量化特性的网络入侵具有较好的检测能力。最后归纳出系统现阶段存在的问题和改进意见,并根据系统的功能提出了后续开发方向。
关键词:网络安全;入侵检测;数据包捕获;PIDS
Implementation of Personal Intrusion Detection System
Abstract
The Intrusion Detection System (IDS) can detect the system or the network resources on the real-time, discover the intruder who intends to enter into a system or a network without warrant in time and prevent users from wrong operation. Based on the basic theory of the intrusion detection and the core technology of intrusion detection, a way of the realization of a simple Personal Intrusion Detection System (PIDS), which based on Windows platform, is well researched. The current security status of the network is analyzed firstly, and then the history of intrusion detection technology and the current core theory of the intrusion detection system are introduced. At last, the network architecture on Windows as well as the structure of capturing and filtering data packets by Winpcap, a tool on development is introduced. After that, the system is realized under the Winpcap system environment. The abnormal detection technology is used in the system. After catching data packets with Winpcap in real-time, extracting probabilistic information about events from the intercepted IP packets and sending them to the intrusion detection module, information is analyzed by method of quantitative analysis. In actual system testing, the system shows a good ability on detecting the quantitative characteristics of network intrusion. Finally, the existed problems and our suggestion during this stage is summed up and according to the function of the system, the proposition is given about the future direction.
Keywords: Network security, Intrusion detection, Package catching, PIDS
目 录
论文总页数:24页
1 引言 1
1.1 网络安全概述 1
1.1.1 网络安全问题的产生 1
1.1.2 网络信息系统面临的安全威胁 1
1.1.3 对网络个人主机的攻击 2
1.2 入侵检测技术及其历史 3
1.2.1 入侵检测(IDS)概念 3
1.2.2 入侵检测系统的分类 4
1.2.3 入侵检测模型 5
1.2.4 入侵检测过程分析 6
1.2.5 入侵检测的发展历史 6
1.3 个人入侵检测系统的定义 7
1.4 系统研究的意义和方法 7
2 个人入侵检测系统的设计 7
2.1 数据包捕