DreamCat 发表于 2005-5-8 15:06:26

RT。

cloudbaby 发表于 2005-5-8 15:45:38

利用IDS可以做到利用开发便宜的LINUX NIDS

DreamCat 发表于 2005-5-10 12:12:14

哪个IDS更好一些呢?

cloudbaby 发表于 2005-5-10 13:20:20

不知道你是问的产品还是自己手动的那?产品我建议你使用北京安氏的IDS那个东西全国评测第一名很不错的!他们有个研发姓曾,不错的是北邮的博士,技术能力比较强所以我感觉很是不错的技术支持没有问题!要是自己弄我建议用LINUX核心搭建!

DreamCat 发表于 2005-5-10 19:52:48

同意版主的看法。还是自己构建一个比较好,有学习的机会。

cloudbaby 发表于 2005-5-11 01:32:52

有事情你说话我记得LINUX下的那个叫DIDS好像是记不得了嘿嘿!

DreamCat 发表于 2005-5-11 14:31:36

找到不少,第一个就是:LIDS Project - Secure Linux System 还是中国人开发的呢。

QUOTE
LIDS is an enhancement for the Linux kernel written by Xie Huagang and PhilippeBiondi. It implements several security features that are not in the Linux kernelnatively.


QUOTE
The Linux Intrusion Detection System (LIDS) is a kernel patch and admin tools which enhances the kernel's security by implementing Mandatory Access Control (MAC). When it is in effect, chosen file access, all system network administration operations, any capability use, raw device, memory, and I/O access can be made impossible even for root. You can define which programs can access specific files. It uses and extends the system capabilities bounding set to control the whole system and adds some network and filesystem security features to the kernel to enhance the security. You can finely tune the security protections online, hide sensitive processes, receive security alerts through the network, and more. LIDS currently support kernel 2.6, 2.4. LIDS is released under GPL.
建议版主整理一下相关的站点,置顶后就方便大家了。

cloudbaby 发表于 2005-5-11 18:56:41

恩好的我找个时间吧所有防火墙的资料还有IDS的另外看看能不能弄些防毒网关的资料和网址提供给大家!嘿嘿

524100jing 发表于 2005-6-1 23:07:56

不是说“如何对扫描进行防范以及监控?”
页: [1]
查看完整版本: 如何对扫描进行防范以及监控?