被动主机信息识别是指通过嗅探发现的方式获取主机的特征信息,主要有旗帜和指纹识别两种方法。主机特征信息是对网络环境下设备的特征描述,而被动方式有对环境影响小的优点。通过结合两种方法完成了被动主机特征信息的实现,为其他网络安全方向的研究提供了数据准备。特别是可以用以对网络入侵检测系统进行改进。
Host Characteristics Information Passively Identifying means acquiring characteristic information of hosts by sniffer discovery.Banner and Fingerprint are two main methods to identify these information.Host characteristic information is description of the host under network environment,and passive mode has the advantage of little influence on the environment.Combined with the two methods the system of passive host characteristics information is completd and realizd.The system could provide data preparation for other network security research,particularly the improvement of network intrusion detection.