摘要
分布式网络环境中主机数据流量的异常通常反映出主机是否遭受病毒、木马等恶意程序的入侵而成为网络攻击中的傀儡机,因此,对主机数据流量进行监测可以尽早发现潜在的危险。研究了基于Cisco路由器的主机数据流量检测的基本方法,并给出了具体的程序实现方法和网络硬件环境配置方法。
Host's traffic anomaly of distribute network often reflected if the host suffered malicious programs of virus and Trojan became to puppet machine. So, Monitoring host's traffic could find potential dangerous earlier. The paper researched the basic method of monitoring host's traffic based on Cisco router, and given specific program realization method and network hardware environment configuring method.