Intelligent Network Forensic System
Gao Xian-wei · Jisuanji fangzhen · 2006
Intelligent network forensic system (INFS) gives us a new method of network protection, and remedies the shortage of the current network security system . The system consists of 5 parts including data collection, data filtering, data storage, management control and intelligent forensic analysis. Filtering rules are used for data collection, reducing the system work, and improving the reliability. The packages of TCP/IP are rebuilt to filter the application layer data. Many methods are used in analysis model to detect intrusion actions, such as protocol analysis, expert system, application layer data reconstruction, intrusion detection. In the network environment, INFS is combined with IDS, firewall, and VPN to serve us a more dependable and strong network security protection system.