论文部分内容阅读
保护企业至关重要的服务器不受攻击,使IT和网络安全经理面临着众多的挑战。缺少专用的安全资源和越来越隐蔽的攻击方式是最令人头疼的两个问题。尽管在过去,入侵检测系统(IDS)是一种受到企业欢迎的解决方案,但它还是不足以阻断当今互联网中不断发展的攻击。入侵检测系统的一个主要问题是它不会在攻击发生前主动阻断它们。同时,许多入侵检测系统基于签名,所以它们不能检测到新的攻击或老式攻击的变形,它们也不能对加密流量中的攻击进行检测。那么,企业还有什么选择呢?入侵防护系统(IPS)是企业安全的下一步合理防护措施。它不仅可进行检测,还能在攻击造成损失前阻断它们,从而将入侵检测系统提升到一个新水平。这两种技术间的区别是企业管理人员已经非常熟悉的:入侵防护阻断了红色代码、尼
Protecting your company’s mission-critical servers from attack gives IT and cyber security managers many challenges. Lack of dedicated security resources and more and more subtle attacks are the two most troubling issues. Although intrusion detection system (IDS) was a popular solution in the past, it was not enough to block the evolving attacks on the Internet today. A major problem with intrusion detection systems is that it does not actively block them before an attack occurs. At the same time, many intrusion detection systems are based on signatures so that they can not detect new attacks or distortions of older attacks, nor can they detect attacks in encrypted traffic. So, companies have any choice? Intrusion Prevention System (IPS) is the next step in the enterprise security reasonable protective measures. It can not only detect, but also block them before they cause damage, bringing the intrusion detection system to a new level. The difference between these two technologies is that business executives are already familiar with: Intrusion Prevention blocks the red code,