基于MIB-Ⅱ的网络安全入侵检测策略
Network Intrusion Detection Strategies Based on MIB-Ⅱ
-
摘要: 为了解决SNMPv1和SNMPv2的安全性问题,同时避免采用SNMPv3的复杂性和缺乏支持性,提出了一种基于MIB- 的网络安全入侵检测策略.该策略采用普遍支持的SNMPv1协议,通过分析设备MIB- 的相关信息,从TCP/IP协议集的数据链路层、网络层、传输层和应用层对网络安全进行多层次监控.实验结果表明,该策略能及时发现网络入侵,适合中小型网络的安全管理.Abstract: A network intrusion detection strategy based on MIB-Ⅱ is proposed. It solves the security problems of SNMPv1 and SNMPv2, and avoids using SNMPv3 that is complicated and only partly supported by manufacturers. SNMPv1 is adopted in the proposed strategy because it is widely supported by manufacturers. By analyzing the data from MIB-Ⅱ, the security of network can be monitored from the data link layer, network layer, transport layer and application layer of TCP/IP protocols. Experimental results show that the proposed strategy can detect network intrusion in time and fit into the security management of small and medium sized networks.
下载: