Intrusion Detecting Based On Protocol Context Analysis

Yl Dong,Ml Shi,H He
2000-01-01
Abstract:How to detect intrusions against a target system is one of the key problems related to Network Security Monitoring System (NMS). This paper presents an approach to detect intrusion based on protocol context analyzing, which is also well implemented in our Agent-Manager NMS. Compared with traditional ones, intrusion detecting based on protocol context analysis enhanced analysis to protocol session content. It complies with the security policy defined by system security administrator and those implemented at firewall and protected systems. All the security rules (policies) are unified into the rule base of our NMS.
What problem does this paper attempt to address?