The invention provides an intrusion detection method based on a Nginx
proxy server. The intrusion detection method comprises the capture step, the
verification step, the transmitting step, the matching detection step and the isolation step. According to the capture step, data packages from all
client ends are captured on the Nginx
proxy server. According to the
verification step, validity
verification is conducted on the captured data packages, and whether the data packages carry legal certificates distributed by a
certificate server is verified. According to the transmitting step, the effective information in the passed data packages of the
client ends is extracted, packaged and then transmitted. According to the matching detection step, the transmitted effective information is received, matching detection is conducted on the effective information according to
weakness codes stored in a
weakness library, and whether the effective information contains codes matched with the
weakness codes stored in the weakness
library is judged. According to the isolation step, the
client ends are isolated to prevent the client ends from conducting hostile
attack on a network. The intrusion detection method and
system can lower the false report rate and the miss report rate due to the fact that the response speed of a detecting
system is far smaller than the transmission speed of the network, and the safety of a
server end is guaranteed maximally.