A New Multi-Function System to Deal with Hacker Intrusion

Weihua Li,Lan Jiang
DOI: https://doi.org/10.3969/j.issn.1000-2758.2005.03.005
2005-01-01
Xibei Gongye Daxue Xuebao/Journal of Northwestern Polytechnical University
Abstract:Our aim is to provide many functions in our new multi-function system for dealing with hacker intrusion. These functions include conventional detection and alert, non-conventional hacker deception and trapping, and restoration of damaged files. Our system is a multi-layer comprehensive active defense system, integrating real-time intrusion detection, alert, security accident restoration, and hacker deception. In the full paper, we explain in much detail how to implement the many functions in our new system. Here we give only a briefing. Compared with conventional IDS (Intrusion Detection System), our new system can not only monitor and trap hackers in real-time mode, but also can realize intrusion tolerance better. The detection function of our system can not only monitor hacker attack but also cleverly track the hacker until the hacker's true source is found. The restoration function of our system can restore important files which have been attacked by hacker or infected by virus. Our new system has been employed successfully on several networks; it can deal effectively with 31 categories of known hacker attacks, whose ways of attack number as many as 2045.
What problem does this paper attempt to address?