论文部分内容阅读
提出了一种抵御分布式拒绝服务(DDOS)的入侵检测系统(IDS)。该IDS由至少两个部件组成,同时在PC级开源软件组件基础上实现了该IDS。系统中的传感器位于企业防火墙与Internet的连接处,分析器位于防火墙内侧。传感器通过运行tcpdump程序提供基本的网络嗅探功能。分析器每隔一小时通过SSH通道从传感器获取tcpdump数据文件,随后对从子目录过滤器中得到的tcpdump过滤器集合进行分析。实验结果表明,该IDS能有效识别DDOS攻击。
An Intrusion Detection System (IDS) against Distributed Denial of Service (DDOS) is proposed. The IDS consists of at least two components, and is implemented on the PC-level open source software component. The sensor in the system is located at the connection between the enterprise firewall and the Internet. The analyzer is located inside the firewall. The sensor provides basic network sniffing by running the tcpdump program. The analyzer gets the tcpdump data file from the sensor every hour through the SSH tunnel, and then analyzes the tcpdump filter collection from the subdirectory filter. Experimental results show that the IDS can effectively identify DDOS attacks.