Intrusion Detection and Prevention Systems

作者: Karen Scarfone , Peter Mell

DOI: 10.1007/978-3-642-04117-4_9

关键词:

摘要: Intrusion detection is the process of monitoring events occurring in a computer system or network and analyzing them for signs possible incidents, which are violations imminent threats violation security policies, acceptable use standard practices. An intrusion (IDS) software that automates process. prevention (IPS) has all capabilities an IDS can also attempt to stop incidents. IPS technologies offer many same capabilities, administrators usually disable features products, causing function as IDSs. Accordingly, brevity term systems (IDPSs) used throughout rest this chapter refer both technologies. Any exceptions specifically noted.

参考文章(9)
Stephen Northcutt, Lenny Zeltser, Ronald W. Ritchey, Scott Winters, Karen Kent, Inside Network Perimeter Security (2nd Edition) (Inside) Sams. ,(2005)
David J. Marchette, V. Nair, S. L. Lauritzen, M. Jordan, J. Lawless, Computer Intrusion Detection and Network Monitoring: A Statistical Viewpoint ,(2001)
Michael Rash, Jake Babbin, Becky Pinkard, Graham Clark, Angela D. Orebaugh, Intrusion Prevention and Active Response: Deploying Network and Host IPS ,(2005)
Rebecca Gurley Bace, Intrusion detection ,(1999)
Peter Mell, Karen Kent, Joseph Nusbaum, None, Guide to Malware Incident Prevention and Handling Special Publication (NIST SP) - 800-83. ,(2005) , 10.6028/NIST.SP.800-83
Peter Mell, Karen Scarfone, Guide to Intrusion Detection and Prevention Systems (IDPS): Recommendations of the National Institute of Standards and Technology National Institute of Standards and Technology (U.S.). ,(2007)
Murugiah Souppaya, Karen Scarfone, Guide to Computer Security Log Management: Recommendations of the National Institute of Standards and Technology [Draft April 2006] National Institute of Standards and Technology (U.S.). ,(2006)