论文部分内容阅读
美国第一国民银行位于北卡罗来纳州分行受到了“红色代码”(一种自我复制的蠕虫程序,专门攻击微软公司出品的 IIS Web 服务器)蠕虫病毒的袭击。但是由于该银行的网络维护部门在公司的网络系统上采用了最新的安全技术——入侵预防系统(IPS),所以有效地隔离了红色代码的侵害,银行的 Web 服务器没有受到红色代码病毒的丝毫损害。尽管大多数网络管理人员早已经关注入侵检测系统(IDS),可是 IPS 对他们来说,却几乎还是一个全新的概念。IDS 和 IPS 从其本质含义上来说相当接近,在没有其他产品能取代它们之前,IPS 作为一项工具几乎总是伴随着 IDS。但是,这两种安全技术之间仍然存在着显著的差别,这类技术差异对 IT 人员而言却意味着系统维护的最终结果可能会有天壤之别。网络 IDS 的用途是监控网络攻击的踪迹、侦察可疑的网络行为。当 IDS 发现了奇怪的网络活动之后,它就会向专业的网络安全维护人员
The First National Bank branch in North Carolina was attacked by a worm called Red Code, a self-replicating worm that attacks Microsoft Web site servers. But since the bank’s network maintenance department used the latest security technology, the Intrusion Prevention System (IPS), on the company’s network system, it effectively isolated the red code and the bank’s web server was not affected by the red code virus damage. Although most network managers have long focused on intrusion detection systems (IDSs), IPS is almost a whole new concept for them. IDS and IPS are fairly close in their nature, and IPS is almost always accompanied by IDS as a tool until no other product can replace them. However, there are still significant differences between the two security technologies, and technical differences of this kind mean to IT personnel that the final result of system maintenance may differ greatly. The purpose of Network IDS is to monitor the trail of cyberattacks and detect suspicious network activity. When IDS finds a strange network activity, it will be to the professional network security maintenance staff