摘要
网络数据包截获、分析功能是实现网络型入侵检测系统的基础。简单介绍了如何采用相关技术实现网络数据包的截获、分析,实现网络特征信息的提取,并结合所开发的入侵误用检测系统给出了结果演示。该功能不仅能够作为入侵检测数据的预处理,也能单独作为网络监控软件安装使用。
How to capture and analyze the network data is the foundation of Network Intrusion Detection. Through pretreatment this software can extract useful feature from network data captured. By recombining and arranging, the data which can be used by the upper detection methods can be saved in the form of a record. Not only can this software be used as a pretreatment software, but also it can be used alone as a network monitor software.
出处
《计算机安全》
2009年第3期24-25,32,共3页
Network & Computer Security