找回密码
 立即注册
Snort封包模式the | 邮电通讯系统 2022-06-27 64 0star收藏 版权: . 保留作者信息 . 禁止商业使用 . 禁止修改作品
?Snort有三种工作模式:嗅探器、数据包记录器、网络入Q检测系统。嗅探器模式仅仅是从网络上读取数据包并作为连续不断的流显示在终端上。数据包记录器模式把数据包记录到硬盘上。网路入Q检测模式是最复杂的,而且是可配置的。我们可以让snort分析网络数据流以匹配用户定义的一些规则,并根据检测结果采取一定的动作。?Snort最重要的用途还是作为网络入Q检测系统(NIDS)。使用简介Snort并非复杂难以操作的软体。Snort可以三个模式进行运作:侦测模式(SnifferMode):此模式下,Snort将在现有的网域内撷取封包,并显示在萤幕上。封包纪录模式(packetloggermode):此模式下,Snort将已撷取的封包存入储存媒体中(如硬碟)。上线模式(inlinemode):此模式下,Snort可对撷取到的封包做分析的动作,并根据一定的规则来判断是否有网路攻击行为的出现。

(? Snort has three working modes: sniffer, packet recorder and network intrusion detection system. Sniffer mode simply reads packets from the network and displays them on the terminal as a continuous stream. The packet recorder mode records packets to the hard disk. The network intrusion detection mode is the most complex and configurable. We can let snort analyze the network data flow to match some user-defined rules, and take certain actions according to the detection results.? The most important use of Snort is as a network intrusion detection system (NIDS). Introduction snort is not a complicated and difficult software. Snort can operate in three modes: sniffermode: in this mode, Snort will retrieve packets in the existing domain and display them on the screen. Packetloggermode: in this mode, Snort stores the captured packets into storage media (such as hard disk). Inlinemode: in this mode, Snort can analyze the captured packets and judge whether there are network attacks according to certain rules.)

[下载]19065840079.rar




上一篇:瑞斯康达NNM v5.0管理软件安装手册
下一篇:公司企事业单位内网安全管理制度(参考)