论文部分内容阅读
防火墙和入侵检测是当前最为常用的安全技术。因为它们在功能上互为补充,所以在许多安全解决方案中结合使用防火墙和入侵检测技术。但是,这种结合却也引入了入侵检测系统检测不到已被防火墙过滤掉的来自外网的攻击等问题,这必须由这两个系统间的通信来解决;另外,防火墙和入侵检测有功能上相同的模块,若分别实现、独立使用这两个系统就忽略了信息的可复用性,造成资源的浪费。因此,该文提出了一种防火墙和入侵检测协同工作的安全构架模型FICoM及其设计。
Firewall and intrusion detection is the most commonly used security technology. Because they complement each other in their functionality, firewalls and intrusion detection technologies are used in many security solutions. However, this combination also introduces the intrusion detection system can not detect the firewall has been filtered out from the external network attacks and other issues, which must be addressed by the communication between these two systems; In addition, firewall and intrusion detection capabilities On the same module, if implemented separately, the independent use of these two systems ignores the reusability of information, resulting in a waste of resources. Therefore, this paper presents a security architecture model FICoM and its design for the cooperation between firewall and intrusion detection.