UkuSifumana kwe-Intrusion Detection (IDS) kunye ne-Prevention (IPS)

Izixhobo zokubeka iliso lwakho inethiwekhi yomsebenzi osolisayo okanye onobungozi

Iinkqubo zokuThungathwa kwe-Intrusion (IDS) zaphuhliswa ekuphenduleni ukwanda kwamanqanaba okuhlaselwa kumanethiwekhi. Ngokuqhelekileyo, isofthiwe ye-IDS ihlolisisa iifayile zokucwangcisa izihostele ezicwangcisiweyo, iifayile zephasiwedi zamagama amapastile kunye nezinye iindawo ekufumaneni ukuphulwa okunokuba yingozi kwinethiwekhi. Ikwabeka iindlela ngendlela yokuthungatha intengiso ukuba irekhode izinto ezityhafisayo kunye nezindlela zokuhlaselwa ezikhoyo kwaye zibaxelele kumlawuli. I-IDS ifana ne-firewall, kodwa ngaphezu kokulinda ukuhlaselwa ngaphandle kwe-intanethi, i-IDS ibonakalisa umsebenzi osolwayo kunye nokuhlaselwa ngaphakathi kwenkqubo.

Elinye isofthiwe ye-IDS inokuphinda iphendule kwiingxubusho ezizifumanayo. Iprojekti ekwazi ukuphendula idla ngokubizwa ngokuba yi-Intrusion Prevention System (IPS). Iyabona kwaye iphendule kwiisongelo eziyaziwayo, emva kweqela elikhulu lemilinganiselo.

Ngokubanzi, i-IDS ikubonisa oko kwenzekayo, ngelixa i-IPS yenza izinto ezisongelayo. Ezinye iimveliso zidibanisa zombini izixhobo. Nazi ezinye iinketho ze-IDS kunye ne-IPS ezikhethiweyo.

Snort ye Windows

I-Snort ye-Windows yinkqubo yokufumanisa ukungena kwenethiwekhi yokuvula inethiwekhi, ekwazi ukwenza uhlalutyo lwengqondo lwangempela kunye nepakethi yokungena kwiinkonzo ze-IP. Ingakwazi ukwenza uhlalutyo lweprotocol, ukufundwa komxholo / ukulingana kwaye kungasetyenziselwa ukufumanisa iintlobo ezahlukeneyo zokuhlaselwa kunye neeprogram, ezifana nokugqithiswa kweetampu, ukuhlaselwa kwamatye, ukuhlaselwa kwe-CGI, i-SMB probes, iinzame ze-OS kunye nokunye okuninzi.

Suricata

I-Suricata yi-software yomthombo evulekile ebizwa ngokuba yi "Snort kwi-steroids." Ikhulula ukufunyanwa kwexesha langempela, ukukhusela ukungena ngaphakathi kunye nokubeka iliso kwinethiwekhi. I-Suricata isebenzisa imithetho kunye nolwimi lwesayina kunye neLua scripting ukufumana iintsongelo ezinzima. Itholakala kwiLuxux, i-MacOS, iWindows nezinye iiplatifomu. Isofthiwe ayikhululekile, kwaye kukho imicimbi emininzi yokuqeqesha imirhumo kawonkewonke ehleliweyo ngonyaka ukulungiselela uqeqesho. Iziganeko zokuqeqesha ezinikezelwe nazo ziyafumaneka kwi-Open Information Security Foundation (i-OISF), eneenkcukacha ze-Suricata.

IDS

I-IDS ye-Bro ihlala iqhutywe ngokubambisana no-Snort. Ulwimi oluthile lwe-domain likaBr aluxhomeki kwiisayinitsha zendabuko. Uloba yonke into ebona kwi-intanethi ye-network yolondolozo. Iprojekti inceda kakhulu ukuhlalutya kwezithuthi kwaye inembali yokusetyenziswa kwiindawo zenzululwazi, iiyunivesithi ezinkulu, amaziko aphezulu kunye neelabhu zophando zokuqinisekisa iinkqubo zabo. Iprojekthi ye-Bro yinxalenye ye-Software Freedom Conservancy.

I-OSS yangaphambili

I-OSS ye-Prelude yi-version evulekile yomthombo we-Prelude Siem, inkqubo entsha yokubonwa kwe-hybrid intrusion eyenzelwe ukuba i-modular, isasazwe, idwala eliqinile kwaye likhawuleze. I-OSS ye-Prelude ifanelekile kwizixhobo eziphuculweyo ze-IT, imibutho yophando kunye noqeqesho. Akujoliswanga ngobukhulu obukhulu okanye amanethiwekhi amaninzi. Ukusebenza kwe-OSS kwangaphambili kunqamle kodwa kusebenza njengesingeniso kwinguqu yezorhwebo.

Defender Defender

I-Malware Defender yinkqubo ye-IPS ehambelana ne-Windows kunye nokukhuselwa kwenethiwekhi kubasebenzisi abakhulu. Ilawula ukuthintela ukungeniswa kwe-intrusion kunye ne-malware. Kuyafaneleka ukusetyenziswa kwekhaya, nangona iincwadi zalo zokufundisa zinzima ukuba abasebenzisi abaqhelekileyo baqonde. Ngaphambili inkqubo yorhwebo, i-Malware Defender yinkqubo yokukhusela i-intrusion (HIPS) ejongene nomsebenzi omnye ojongene nomsebenzi osolisayo.