摘要
入侵防护系统为系统安全带来新的保障手段,结合入侵监测的特征识别和误用统计思想,提出基于双层过滤的入侵防护系统,通过设计易于扩展的规则存储方案和基于行为约束的检测机制,在应用层与内核层对系统操作进行过滤,并作协同检查。实验证明,该方案可以满足被保护系统的安全性需要。
Intrusion Prevention System implements a new way for system security. Combining the misuse detection and anomaly detection theory of IDS, propose the double - filter used Intrusion Prevention system. It uses a scalable policy storage technique and a behavior restriction based detection mechanism. By filtering and checking function call in both kernel and system layer, it reaches a high security feature ,which is proved by experiments.
出处
《微处理机》
2009年第3期53-56,共4页
Microprocessors