摘要
在对已有的蜜网模型中防火墙、入侵检测的部署仔细研究后,指出蜜网也有不安全性,在此基础上提出如用DMZ区(非武装区,不信任区)、两层防火墙防止对内部网的侵害,用NIDS(网络入侵检测系统)和限制流量的方法防止对外部网的攻击,从而形成了一个新的蜜网、入侵检测技术、防火墙构成的方案.
Through carefully analyzing the arrangement of firewall and intrusion detection in the existing honeynet model, this paper points out unsafety of the honeynet. It also points out that DMZ district (demilitarized zone) and two firewalls can prevent the intrusion for inside network, and NIDS (network intrusion detection system) and flow restriction can prevent the attack for outside net work. As a result, a new system of honeynet, intrusion detection and firewall has been set up.
出处
《四川师范大学学报(自然科学版)》
CAS
CSCD
北大核心
2005年第1期119-122,共4页
Journal of Sichuan Normal University(Natural Science)
关键词
蜜网
防火墙
入侵检测
Honeynet
Firewall
Intrusion Detection