随着互联网应用的普及和不断深入,网络威胁也给人们的工作和生活带来了重大挑战.为了应对这些挑战,给广大网民营造一个安全、可信的互联网环境,文章研究了威胁信息溯源问题,分析了现有威胁溯源方法存在的不足,从实践角度出发提出了一种基于入侵检测系统报警信息和rootkit的威胁溯源方案.文章设定了本方案的假设条件,分析了该方案的可行性,指出了方案面临的挑战.
With the popularization and development of Internet application, Internet-based network threat has posed a serious challenge to everyone's work and life. In order to deal with this challenge as well as create a safe and trusted Internet environment for the cyber citizens, this paper reads up the problem of threat information traceback, analyzes the drawbacks of the existing method of threat traceback, proposes a threat traceback scheme which is based on the alarms of intrusion detection system and rootkit technology. This paper sets up the assumption of the scheme according to the fact when traceback threat, analyzes the feasibility, proposes the challenge.