论文部分内容阅读
安全监控与审计产品主要针对网络、主机、数据库等,获取、监测、记录、分析其状态信息和敏感操作,依据安全策略判断是否存在违规行为和异常行为,并进行告警和阻断。可以说,与入侵检测系统等其他针对外部威胁的网络安全产品相比,安全监控与审计产品更侧重于应对网络内部威胁。本文将从应用需求、主要分类、性能指标等3个方面,对安全监控与审计产品进行简要介绍。
Security monitoring and auditing products are mainly for the network, host, database, access to, monitoring, recording, analysis of its status information and sensitive operations, according to the security policy to determine whether there are irregularities and abnormal behavior, and alarm and blocking. It can be said that, compared with other network security products such as intrusion detection system and other external threats, security monitoring and audit products are more focused on addressing internal network threats. This article will be from the application requirements, the main classification, performance indicators, three aspects of safety monitoring and auditing products are briefly introduced.