Abstract
Abstract Network security is frequently adverted and researched in recent years because the cases that hackers attacked famous websites emerge in an endless stream, and the Intranet is beset by the nameless attacks any time. Most enterprises utilize the Firewall, Intrusion Detection System (IDS) or Intrusion Detection and Prevention System (IPS) to prevent the Intranet from the attacks, presently. However, this protection method can just prevent the Intranet from the attacks from the Internet, but can’t stop the infected stations re-infecting others in the Intranet. Because IDS or IPS is usually placed in the doorway between the Intranet and the Internet, the despiteful behavior which passes through the only doorway just could be captured or dropped. Nevertheless, it has been pointed out that most of the attacks or worms (more than 80%) actually are launched from the inside (infected hosts). In this thesis, a Portable Intrusion/Security Analyzer (PISA) is proposed to analyze the safety and health conditions of an enterprise network. The PISA is very easy to use (almost plug and play), portable (implemented on a Notebook), and cost-effective. Just plug the PISA into any port of a L2 switch, and then the traffic passing through this switch will be automatically forwarded to the PISA for inspection. The report system can real-time indicate who are launching the attacks, who are victims, and what kinds of attacks are launched. Furthermore, the PISA can also communicate with the L2 switch to block the ports that are launching the attacks (such as SYN flooding) for a period of time to isolate the attacking hosts. The proposed PISA can not only detect the intrusions carried in the packets, but also act as an “in-line” mode to take proper actions (such as dropping malicious packets) if an IPS, instead of an IDS, is embedded in the PISA.