论文部分内容阅读
某集团公司的总部在上海,并在香港和其它地区设有分支机构,属于制造型企业。总部的计算机网络中心拥有公司最重要的设备和信息数据,其中最主要的应用为整个集团的 ERP 系统。各分支机构与集团总部采用租用专线来连接,形成企业自己的专网,网络中心同时还通过128K 的 DDN 专线与 Internet 相连,内部员工可以对外进行浏览访问和使用自己的 Mail 系统,外界的人员也随时能访问谈集团的 Web 网站,网络中基本采用了 windows 系统。需求分析该集团公司的防火墙配置比较简单,内部或外部的人员可以轻易的进行恶意攻击(如基于 IPC 的远程控制、IP 地址盗用或基于 Web 的 Unicode 攻击和printer攻击等)。为了保证网络的正常运行,公司选用了金诺网安入侵 KIDS 系统检测。KIDS 是综合的入侵检测系统,它将主机入侵检测和网络入侵检测相结合,分别从计算机和网络的各个关键点收集违反安全策略的行为或被攻击的迹象,并且可以根据用户的需要实时报警和响应;可以防止来自外网的黑客入侵,也可以制止来自内网的恶意行为、误操作或资源滥用。系统设计金诺网安入侵检测系统是由网络传感器(NIDS)、主机传感器(HIDS)和管理控制台(Console)组成的分布式系统。网络传感器从网络数据包发现入侵的痕迹,主机传感器对主机系统的系统活动事件、日志信息进行分析,发现可疑行为。管理控制台对所有的传感器进行统一的集中式管理和监控。系统管理员可
A group company is headquartered in Shanghai, and in Hong Kong and other regions with branches, are manufacturing enterprises. The headquarters computer network center has the company’s most important equipment and information data, of which the most important application is the entire group’s ERP system. The branches and group headquarters using leased line to connect to form their own private network, the network center also through the 128K DDN dedicated line connected with the Internet, internal staff can browse external access and use their own Mail system, outside staff At any time to talk about the group’s Web site, the network basically used the windows system. Needs analysis The group company’s firewall configuration is relatively simple, internal or external personnel can easily malicious attacks (such as IPC-based remote control, IP address theft or Web-based Unicode attacks and printer attacks, etc.). In order to ensure the normal operation of the network, the company chose Jinnuo network security KIDS system detection. KIDS is a comprehensive intrusion detection system that combines host intrusion detection and network intrusion detection to collect violations of security policies or attacks from various points in the computer and network respectively and to alert users in real time according to user needs Response; can prevent hackers from outside the network invasion, but also can stop malicious acts from the network, misuse or abuse of resources. System Design Jinnuo network security intrusion detection system is a network of sensors (NIDS), host sensors (HIDS) and management console (Console) composed of distributed systems. The network sensor finds traces of intrusion from network packets, and the host sensor analyzes the system activity events and log information of the host system and finds out suspicious behaviors. The management console centrally manages and monitors all sensors in a unified manner. System administrator can