摘要
针对IP地址资源的匮乏和网络攻击手段的多样化,NAT环境下的网络安全性要求不断提高。文章研究了在NAT环境下的安全策略,并引入入侵重定向的概念。在Apriori算法挖掘的基础上,引入关联规则兴趣度,对入侵行为进行深度挖掘,将具有威胁的网络访问重定向到特定环境中,通过访问规则数据库与防火墙规则、IDS数据库的交互,提高了网络防御的主动性,与结合NAT的防火墙技术实现了对网络的双重保护。
For the lack of resources of IP address and diversification of network attack measures, the requirement of network security in NAT environment is raised continuously. This paper research on the security policy in NAT environment, and presents the concept of intrusion redirection. Based on Apriori algorithm mining, this paper proposes Interest degree of association rules, performs deep mining of intrusion behaviors, redirects the network access with threat into a specific environment, performs interaction with firewall rules and IDS database through accessing the rule database, improving the network defense initiative, and the firewall technology combined with NAT can implement duplex protection of the network as well.
出处
《计算机与数字工程》
2011年第7期113-116,共4页
Computer & Digital Engineering
基金
北京市教委科技项目(编号:KM200710011001)资助