- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
nids与防火墙联动(NIDS and firewall linkage)
nids与防火墙联动(NIDS and firewall linkage)
This article is contributed by a785842883
DOC documents may experience poor browsing on the WAP side. It is recommended that you first select TXT, or download the source file to the local view.
Experimental principle
Fwsam-snort
Guardian
Iptables
Snortsam
First, the use of Guardian to achieve Snort and iptables linkage, Guardian is based on Snort and iptables an active firewall, running in the background. Guardian analysis of the snort alarm log alert file (default path /var/log/snort/), according to certain judgments, automatically add some malicious IP to the iptables input chain, and discard its datagram. When Guardian exits, it deletes the rules previously inserted into the iptables input chain. Two. Use snortsam plug-in to achieve Snort and iptables linkage, SnortSam is Snort Intrusion Prevention plug-in. It works by adding new responses to the snort rule, which, once triggered, changes the firewall or router. This change usually blocks or prohibits traffic from or to a particular IP address for a period of time. SnortSam works with Checkpoint, Firewall-1 firewalls, Cisco PIX firewalls, and iptables firewalls. There are two basic components of SnortSam: plug-ins and proxies. This structure allows you to allow firewall rules or ACL to terminate after a predefined period of time. The agent is responsible for modifying routers and firewalls, and can build and remove firewall rules. It has a timer function that allows it to terminate a rule at the preset time. Other intrusion prevention applications can permanently modify firewalls and routers, which is obviously not ideal. This structure allows a single sensor to interact with many different firewalls and routers. If you have a sensor that is used to protect a large environment with many firewalls, sensors can control each firewall based on the triggered rules. A plug-in is a standard snort output plug-in that is used to send instructions to an agent when a rule is fired. Thes
您可能关注的文档
- 土建施工员应该知道的数据(The data that the builder should know).doc
- 土建管理(Civil Engineering Management).doc
- 土楼(Tulou).doc
- 土豆的营养价值(The nutritional value of potatoes).doc
- 圣典(Canon).doc
- 圣心慈悲(The sacred heart of compassion).doc
- 土豆预防高血压海星之谜告诉你那些你不知道的养生食物(Potatoes prevent the mystery of high blood pressure starfish, telling you what you don't know about health foods).doc
- 圣斗士144人出招表(Saint Seiya 144 shift table).doc
- 图放大代码(Figure enlarge code).doc
- 在 word 中如何输入分数(How do I enter a fraction in word).doc
- 2026秋季中国工商银行集约运营中心(佛山)校园招聘20人备考题库含答案详解(培优).docx
- 中国农业银行宁波市分行2026年度校园招聘214人备考题库附答案详解(夺分金卷).docx
- “梦工场”招商银行长沙分行2026寒假实习生招聘备考题库附答案详解(轻巧夺冠).docx
- 2026贵州省公共资源交易中心定向部分高校选调优秀毕业生专业技术职位考试备考题库完整参考答案详解.docx
- 中国建设银行建信金融资产投资有限公司2026年度校园招聘8人备考题库含答案详解(a卷).docx
- 中国农业银行宁夏回族自治区分行2026年度校园招聘146人备考题库及一套参考答案详解.docx
- 门头沟区青少年事务社工招聘1人备考题库附答案详解(模拟题).docx
- 中国建设银行运营数据中心2026年度校园招聘20人备考题库含答案详解ab卷.docx
- 中国建设银行建银工程咨询有限责任公司2026年度校园招聘9人备考题库及答案详解(有一套).docx
- 2026秋季中国工商银行重庆市分行校园招聘270人备考题库含答案详解(完整版).docx
原创力文档


文档评论(0)