Network safety guarded distributing invading detection and internal net monitoring system and method thereof

A technology for network security and intrusion detection, applied in transmission systems, digital transmission systems, data exchange networks, etc., can solve problems affecting data flow speed, lack of internal network monitoring, poor scalability, etc., to improve fault tolerance and reliability, The effect of standardizing the behavior of internal operators and blocking external intrusion

CN1564530AInactive Publication Date: 2005-01-12沈春和
0 Cites 32 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2005-01-12
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The method is suitable to exchange type LAN, sharing type LAN, multiple sub networks distributed type large and medium size type network. The system including three layers type structure contains detector in host, CPU, management and control center, and background database. The method includes following procedures: establishing safety rules; based on safety rules, intrusion detection and monitoring and controlling Intranet according to IP address and MAC address; breaking, alarming intrusion and violation, and recording it to background database; auditing recorded information; recovering destroyed data etc. The integrated system possesses features of favorable expansibility, maintainability, portable and reuse.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to a system and method for network security protection, in particular to a distributed intrusion detection and intranet monitoring system and method for network security protection. The system and method can provide network security guarantees for internal LAN and network users connected to the Internet. It is suitable for secret-related networks with strict requirements on network security, as well as financial, insurance, electric power, tobacco, education, securities, etc. Large and medium-sized networks with large networks, complex network conditions, and centralized management of network security. Background technique

[0002] With the wide application of the Internet and the rapid development of e-commerce, higher and higher requirements are put forward for network security technology, and network security has become an important issue of concern to governments and enterprises all over the world. At present, anti-virus soft...

Examples

Embodiment Construction

[0022] For an embodiment of the network security protection system of the present invention, see figure 1 . The distributed intrusion detection and intranet monitoring system for network security protection has a three-layer distributed structure, including a detector 1, a central controller 2, a management monitoring center 3 and a background database 4. The detector 1 includes a network detector 101 and a host detector 102 . The network detector 101 and the host detector 102 are connected with the central processing unit 2 , the management monitoring center 3 and the background database 4 .

[0023] Embodiment Network detector 102 is distributed in sensitive parts of the network, based on advanced network message capture technology, monitors the data flow of the network in real time, analyzes the data flow in real time according to the security rules formulated by the management and monitoring center 3, and finds network attacks or network attacks. In the case of violation...