论文部分内容阅读
TCP/IP协议的开放性和简单性使互联网取得巨大成功,但也带来了网络的安全和管理方面的问题,使得对当前网络通信行为的掌握成为网络管理中的基本任务之一。对网络行为的监测不仅有助于及时了解校园网当前应用状况,而且也可以发现网络中存在的一些安全和管理隐患。本论文提出了一种主动检测当前网络通信行为的方法,该方法根据给定检测需求,自动从相应网关设备中提取有关的网络通信日志数据,通过分析统计获得目标对象的网络通信行为。在校园网环境下的实验中,使用该方法不仅可以知道校园网当时通信行为的特点,而且还可以发现疑似代理服务器和有震荡波病毒的计算机。
The openness and simplicity of the TCP / IP protocol have made the Internet a huge success, but it also brings about network security and management problems. As a result, the current network communication behavior has become one of the basic tasks in network management. The monitoring of network behavior not only helps to keep abreast of the current status of campus network applications, but also can find some hidden dangers in the network security and management. This paper proposes a method to proactively detect the current network communication behavior. The method automatically extracts the relevant network communication log data from the corresponding gateway device according to the given detection requirement, and obtains the network communication behavior of the target object through analysis and statistics. In the experiment of campus network environment, using this method can not only know the characteristics of campus network communication behavior at that time, but also can find the suspected proxy server and the computer with Sasser virus.