网络入侵检测系统是一种通过实时监测网络以发现入侵攻击行为的安全技术。随着入侵检测技术的发展进步,目前已经出现了各种各样的网络入侵检测系统。文章在综合分析各种入侵检测技术的基础上,构建了一个基于Snort的网络入侵检测系统,能快速发现入侵行为,实时报警,提高网络防御体系的完整性。该系统采用基于规则的网络信息搜索机制,对数据包进行内容的模式匹配,从中发现入侵和探测行为。
Network intrusion detection system is a security technology to detect the intrusion through monitoring network in runtime. And that, with the advancement of the technology to detect the intrusion, there have many type of the network intrusion detection system. Based on comprehensive analysis of all types of intrusion detection technology,this paper comtructs a Snort-based network intrusion detection system, which can quickly find intrusion and generate real-time alerts, improve the integrity of the network defense system. The system uses rule-based search mechanism for network information and pattern matching for data packets, discover intrusion and detection behavior.