论文标题

入侵检测和预防系统的概述

An overview of Intrusion Detection and Prevention Systems

论文作者

Coulibaly, Keturahlee

论文摘要

网络威胁不仅在增加,而且在其成熟和难以检测的情况下也在增加。多年来,攻击已成为私人和公众以及政府部门的国家/全球威胁。这是一个日益严重的问题,组织正在采取措施减少,检测和防止威胁。为此,他们需要使用配备功能的系统来执行这些步骤中的任何一个,并为其使用的网络类型开发它们,例如有线或无线。这些系统之一是入侵检测系统(IDS),可以用作威胁或攻击的第一种防御机制或二级防御机制。网络中可能会发生不同类型的攻击,例如拒绝服务(DOS)/分布式拒绝服务(DDOS),端口扫描,恶意软件或勒索软件,依此类推,IDSS具有检测能力。协助缓解此类攻击,还有一些入侵预防系统(IPS)的作用与IDS的作用不同。与IDS不同,它们不仅检测到威胁,而且可以防止其破坏网络,还可以与IDS一起使用IPSS来加倍防御。本文概述了IDS及其分类和IPS。它将详细介绍使用IDS,IPS和混合动力车(例如Intrusions Tefuction Tefuction Hection Systems(IDPS等))的典型好处和局限性,将进一步讨论。它还将概述使用ML进行制作的发展,以及如何用于改善这些系统以及它们产生的困境以及对抗它们的可能方法。

Cyber threats are increasing not only in their volume but also in their sophistication and difficulty to detect. Attacks have become a national/global threat as they have targeted private and public, as well as government sectors over the years. This is a growing issue and organisations are taking steps to reduce, detect and prevent threats. To do this they need to use systems that are equipped with the capabilities to do either of those steps and develop them for the type of networks they use, for instance wired or wireless. One of these systems are Intrusion Detection Systems (IDS), which can be used as the first defence mechanism or a secondary defence mechanism of a threat or an attack. There are different types of attacks that can occur in a network, such as Denial of service (DoS)/Distributed Denial of Service (DDoS), port scanning, malware or ransomware and so forth that IDSs have a capability of detecting. Assisting in the mitigation of such attacks, there are also Intrusion Prevention Systems (IPS) whose role has a different purpose than that of IDSs. Unlike IDSs they not only detect threats but prevent them from disrupting the network, IPSs can be used in conjunction with IDSs to double the defences. This paper provides an overview of IDS and their classifications and IPS. It will detail typical benefits and limitations to using IDSs, IPSs and the hybrids (such as Intrusions Detection Prevention Systems (IDPSs and more)) which will be discussed further. It will also outline developments in the making using ML and how it is used to improve these systems and the dilemmas they produce and possible ways to counter act them.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源